Attorneys  Joaquin  Gamboa  and  Marc  Lindsey 
say  cloud  computing  requires  new  tactics  to  get  the  right  license  at  the  right  price. 


Inside 


SEPTEMBER  8,  2008 

VOL.  42,  NO.  36  S5/C0PY 


News  Analysis 

The  new  Chrome 
browser  is  the  latest 
weapon  in  Google’s  plan 
to  replace  Windows 
with  the  Web. 


The  feds  may  finally 
be  getting  serious 
about  enforcing 
HIPAA’s  privacy  and 
security  rules,  pagi 


ill:  H-1B  critic 
Norman  Matloff  spells 
out  what’s  wrong  with 
the  visa  program  and 
why  it’s  tough  to  be 
40  in  IT.  e  12 


Opinion 

Impeach  e-voting:  We 
can’t  trust  systems 
that  lack  paper-based 
backups. PAGE  16 


Careers 

IT  workers  who  lie 
low  when  faced  with 
possible  layoffs  are 
reacting  in  exactly  the 
wrong  way. 


The  down  economy 
doesn’t  mean  tough 
times  for  some  high- 
profile  CIOs. 

COMPUTERWORLD.COM 


IBM  System  x3550™  Express.  It’s  designed  to  stay  up  and 
running  and  help  reduce  system  downtime.  In  fact,  it  can 
even  identify  a  potential  problem  before  it  becomes  one. 
And  if  you  ever  have  to  replace  a  component,  you  can  do 
that  without  having  to  shut  down.  Just  one  more  way  the 
x3550  Express  keeps  downtime  down. 

From  the  people  and  Business  Partners  of  IBM. 

It’s  innovation  made  easy. 


RUN  YOUR  CRITICAL  APPLICATIONS  WITH  CONFIDENCE. 


PN:  7978EJU _ _ 

Featuring  up  to  two  Quad-Core  Intel®  Xeon®  Processors  E5430  2.66GHz 
Hot-swap  redundant  cooling  for  high  availability 
Includes  IBM  Director  and  PowerExecutive  to  help  manage  power 
consumption,  increase  uptime,  reduce  costs  and  improve  productivity 

3-year  on-site  limited  warranty2  on  parts  and  labor 


IBM  SYSTEM  STORAGE™ 
DS3400  EXPRESS  KIT 

$13,793 

OR  S352/MONTH  FOR  36  MONTHS' 


PN:  1726-42U 


IBM  TIVOLI"  CONTINUOUS  DATA  PROTECTION  FOR  FILES 


$42  per  user 


PN:  D613ALL 


All-in-one  kit  makes  it  easier  to  migrate  from  your  DAS  network  to  SAN 
Includes  IBM  System  Storage  DS3400  Dual  Controller,  four  IBM  Emulex  42C2069 
4Gb/s  PCI  Express  HBAs,  Brocade  SAN  8  Port  Fibre  Channel  switch  (16  total 
ports),  twelve  4Gb/s  SFPs,  and  eight  5-meter  optical  LC  cables 
Emulex  EZ  Pilot™  installation/management  software  included 


Save  and  recovery  technology  enables  file  recovery  to  any  point  in  time 

Continuous  Data  Protection  (CDP)  protects  your  data  from  the  aftermath  of  a  virus 
attack  or  user  error 

Up  to  3  backup/replication  areas  help  protect  against  corruption,  file  loss  or 
system  loss 


COMPLIMENTARY  SYSTEMS  ADVISOR  TOOL 


Want  to  fintt  the  right  server  or  storage  system  for  you? 

Our  Systems  Advisor  Tool  can  help.  Just  give  the  tool  a  little 


pHl 


Mt§s 


input,  and  it  will  identify  products  that  can  help  meet  your 
business  needs.  Get  started  now  at  ibm.com/systems/uptime 


=  =  ==£=  express 
^=F=ETE:  advantage7 


ibm.com/systems/uptime 

1  866-872-3902  (mention  6N8AH04A) 


i.  IBM  Global  Financing  offerings  are  provided  through  IBM  Credit  LLC  in  file  United  States  and  other  IBM  subsidiaries  and  divisions  worldwide  to  qualified  commercial  and  government  customers,  Monthly  payments  provided  are  for  planning  purposes 
only  and  may  vary  based  on  your  credit  and  other  factors.  Lease  otter  provided  is  based  on  an  FMV  lease  of  36  monthly  payments.  Other  restrictions  may  apply.  Rates  and  offerings  are  subject  to  change,  extension  or  withdrawal  without  notice. 

7  IBM  hardware  products  are  manufactured  from  new  parts,  or  new  and  serviceable  used  parts.  Regardless,  our  warranty  terms  apply.  For  a  copy  of  applicable  product  warranties,  visit  ibm.com/servers/support/machine_warranties  or  write  to:  Warranty 
Information.  P.O.  Box  12195,  RTP,  NC  27709,  Attn,  Dept  JDJA/B203.  IBM  makes  no  representation  or  warranty  regarding  third-party  products  or  services,  including  those  designated  as  ServerProven®  or  ClusterProven*  Telephone  support  may  tie  subject 
to  additional  charges.  For  on-site  labor.  IBM  will  attempt  to  diagnose  and  resolve  the  problem  remotely  before  sending  a  technician.  On-site  warranty  is  available  only  tor  selected  components.  Optional  same-day  service  response  is  available  (on  select 
systems]  at  an  additional  charge.  IBM.  the  IBM  logo,  IBM  Express  Advantage,  System  x  and  System  Storage  are  trademarks  of  International  Business  Machines  Corporation  in  the  United  States  and/or  other  countries.  For  a  complete  list  of  IBM  Trademarks, 
see  ibm.com/legal/copytrade.shtml.  Intel,  the  Intel  logo,  Xeon  and  Xeon  Inside  are  trademarks  or  registered  trademarks  of  Intel  Corporation  in  the  U.S.  and  other  countries.  All  other  products  may  tie  trademarks  or  registered  trademarks  of  their  respective 
companies  Ail  prices  and  savings  estimates  are  based  upon  IBM’s  estimated  retail  selling  prices  as  of  03/24/2008.  Prices  and  actual  savings  may  vary  according  to  configuration.  Resellers  set  ttieir  own  prices,  so  reseller  prices  and  actual  savings  to  end 
users  may  vary.  Products  are  subiect  to  availability.  Hus  document  was  developed  tor  offerings  in  the  United  States.  IBM  may  not  offer  the  products,  teatures,  or  services  discussed  in  this  document  in  other  countries.  Prices  are  subject  to  change  without 
notice.  Starting  price  may  not  include  a  hard  drive,  operating  system  or  other  features.  Contact  your  IBM  representative  or  IBM  Business  Partner  tor  the  most  current  pricing  in  your  geographic  area.  ©  2008  IBM  Corporation.  All  rights  reserved. 


FOR  BREAKING  NEWS  GO  TO  COMPUTERWORLD.COM 


■  NEWS  DIGEST 

4  Post-Katrina  disaster  recovery 
upgrades  leave  IT  departments 
in  New  Orleans  better  prepared  for 

Hurricane  Gustav.  |  Microsoft 

expands  its  licensing  options  for 

running  Vista  virtually. 


6  California’s  legislature 

softens  a  data  breach 
bill  that  was  vetoed  last 
fall.  |  A  testing  bottle¬ 
neck  results  in  a  shortage 
of  Intel's  Atom  processor. 


8  The  U.S.  Army  awards  iRobot  a 
$200  million  contract  to  supply 

robots  for  use  on  the  battlefield. 


■  NEWS  ANALYSIS 

9  Google  Adds  a  Weapon  in  Its 
Battle  to  Kill  Windows.  Google 
hopes  its  new  Chrome  browser  will 
launch  a  widespread  rejection  of 
Windows-based  systems. 

10  Feds  Finally  Put  Teeth 
Into  HIPAA  Enforcement.  A 

stringent  settlement  over  "possible 
violations”  of  HIPAA's  security  and 
privacy  rules  could  signal  the  end  of 
lax  enforcement  of  the  law. 


■  DEPARTMENTS 

12  The  Grill:  Longtime  H-1B  critic 
Norman  Matloff  explains  what’s 
wrong  with  the  program,  why  it’s 
tough  to  be  40  in  IT,  and  what  he  tells  ; 

computer  science  students  about 
their  future  careers.  ! 


26  IT  Mentor:  Cloud-enabling 
Your  Software  Licenses. 

Without  the  right  license  at  the  right 
price,  cloud  computing  could  put 
your  company  and  your  job  at  risk, 
say  attorneys  Joaquin  Gamboa  and 
Marc  Lindsey.  \ 


■  OPINIONS 

2  Editor’s  Note:  Scot  Finnie 
sees  Google’s  Chrome  as  the  first 
shot  fired  in  a  war  over  platform 
dominance,  and  a  clear  marker  of 
things  to  come. 

16  Sharon  Machlis  isn’t  /l 
willing  to  entrust  democ¬ 
racy  to  electronic  systems 
that  lack  a  paper-based  backup. 

38  Paul  Glen  says  an  important 
part  of  your  job  as  a  manager  is  to 
help  people  make  peace  with  the 
new  meaning  of  the  word  job. 

44  Frankly  Speaking:  Frank 

Hayes  wonders  how  IT  will  deal  with 
Google’s  Chrome,  which  he  sees  as 
the  front  end  for  a  Web-browsing 
software-as-a-service  offering. 


36  Security  Manager’s 
Journal:  Building  a  Security 
Org  From  Scratch.  Coming  in 
as  the  security  guru  in  a  company 
with  no  infosec  program  at  all  is 
a  great  opportunity.  Doing  it  twice 
is  even  better. 


40  Career 
Watch:  $10  mil¬ 
lion  a  year?  Some 
V  IT  leaders  aren’t 
hurting  at  all. 


42  Shark  Tank:  A  pilot  fish  trying 
to  track  down  a  problem  with  custom 
software  comes  to  find  out  he’s  miss¬ 
ing  one  vital  piece  of  information. 

■  ALSO  IN  THIS  ISSUE 


Online  Chatter 


3 

42 


■  FEATURES 

18  Gathering  Green 

COVER  STORY:  We  suggest  some  low-hanging  fruit  for 
today  and  stretch  goals  for  tomorrow  that  will  help  you 
save  green  by  going  green. 

32  The  Power  of  One 

A  project  that  consolidated  13  billing  systems  into  one  is 
saving  Verizon  Wireless  $20  million  annually. 

34  How  to 
Save  Your  Job 

Q&A:  Janet  Banks,  formerly 
of  Citibank  and  FleetBoston, 
asserts  that  IT  workers  who 
feel  that  their  jobs  are  threatened 
often  react  in  exactly  the  wrong  way. 


Company  Index 


COVER  ILLUSTRATION  BY  ELIZABETH  LADA 


■  EDITOR’S  NOTE 

~T — ® 

t  rmnie 

The  Next  Wave 

OU  HAVE  TO  WONDER  whether  Tim  Berners- 
Lee,  inventor  of  HTTP  and  the  Web  browser,  had 
a  sense  of  where  it  all  would  lead.  All  these  years 
later,  does  anyone  know?  The  Web  is  the  invention 
that  keeps  on  giving. 


The  conception  of  the 
Web  browser  was  bril¬ 
liant,  but  the  browser  was 
a  relatively  simple  piece 
of  software.  All  the  more 
remarkable,  then,  that  it’s 
been  at  the  heart  of  a  se¬ 
ries  of  transforming  trends 
in  computing. 

Apparently,  that  trans¬ 
formation  isn’t  over.  For 
more  than  10  years,  experts 
have  predicted  the  end  of 
the  dominance  of  operating 
systems,  with  the  rise  of 
the  Internet  as  the  primary 
application  platform.  But 
the  pundits  were  early  to 
that  party;  we  have  never 
been  close  to  the  end  of  the 
dominance  of  Windows 
and  other  desktop  operat¬ 
ing  systems.  For  the  mo¬ 
ment,  Microsoft’s  mantra, 
“Control  the  platform  at 
the  operating  system,”  con¬ 
tinues  to  be  a  safe  strategy. 

But  if  ever  there  was  a 
beginning  of  the  end,  that 
moment  arrived  last  Tues¬ 
day  when  Google  released 
the  first  beta  of  its  Chrome 
Web  browser.  The  new 
product  is  being  designed 
from  the  ground  up  as  a 
next-generation  client  plat¬ 
form  for  enterprise  applica¬ 
tions  —  the  potential  client 
engine  for  software-as-a- 


service  products,  cloud 
computing  and  Web  2.0 
for  the  enterprise.  (See  the 
story  on  page  9,  Frankly 
Speaking  on  page  44,  and 
more  news,  reviews  and 
analysis  on  the  Web  at 
www.computerworld.com/ 
chrome .) 

Google  claims  that  as  a 
multiplatform,  multiple- 
instance  browser  with  a 
powerful  JavaScript  com¬ 
piler,  Chrome  will  be  more 
reliable  and  use  memory 
more  efficiently  than  other 
browsers.  The  company 
promises  that  its  browser 
will  be  able  to  juggle  mul¬ 
tiple  applications,  block 
a  single  bad  app  from 
bringing  down  the  stack 
and  zip  through  JavaScript 
instructions.  It  should  also 
make  quick  work  of  AJAX 
and  other  Web  2.0-enabling 
technologies.  Many  of  those 
claims  echo  Microsoft’s 
descriptions  of  Windows 

EH  The  beginning 
of  the  end  of  the 
dominance  of  the 
desktop  OS  may 
have  arrived  with 
Google’s  release  of 
the  Chrome  beta. 


3.1,  95  and  98.  Chrome  is 
being  designed  to  run  Web 
apps  the  way  a  robust  oper¬ 
ating  system  does. 

That  may  sound  laugh¬ 
able  right  now.  As  intrigu¬ 
ing  as  Google  Docs  is,  for 
example,  it  offers  little  real 
competition  to  Microsoft 
Office  in  the  enterprise. 
But  current  Web  apps  are 
little  more  than  placehold¬ 
ers  for  what’s  yet  to  come 
from  third-party  software 
providers.  The  power  and 
functional  reach  of  Web 
apps  takes  on  a  whole 
new  significance  when 
underpinned  by  a  robust 
browser-based  app  plat¬ 
form.  Chrome’s  release 
is  like  a  starting  flag  that 
tells  software  makers:  “Let 
the  development  begin.” 

That’s  why  Chrome  is 
more  than  just  a  shot  across 
the  bows  of  enterprise 
platform  and  application 
providers.  It’s  the  first  shot 
fired  in  a  war  about  to  be 
waged  over  platform  domi¬ 
nance.  At  the  same  time, 
it’s  welcome  support  for  the 
Web-based  direction  en¬ 
terprise  apps  are  taking.  As 
such,  it  will  have  complex, 
profound  and  unpredictable 
effects  on  enterprise  IT. 

So  far,  Google  has  done 


little  more  than  take  the 
initiative  to  show  the 
world  the  kind  of  browser 
that’s  needed.  Chrome  is 
robust  enough  to  support 
the  browser-as-platform 
notion.  So,  does  Google 
want  to  own  the  platform, 
or  is  it  trying  to  goad 
browser  makers  into  de¬ 
livering  reliable,  robust 
products  that  can  spur  ap¬ 
plication  development? 

Many  observers  believe 
Google  is  after  the  whole 
enchilada,  but  I’m  not  so 
sure.  If  I  were  planning  to 
own  the  platform,  I’d  ship 
Chrome  with  a  killer  app, 
make  deals  with  OEM  PC 
makers  and  try  to  deliver 
a  finished  environment. 

I’d  be  able  to  showcase  my 
partners’  enterprise  appli¬ 
cations  taking  full  advan¬ 
tage  of  the  new  platform. 

Perhaps  Google  is  mind¬ 
ful  that  the  huge  market 
share  for  Internet  Explorer 
places  the  ball  firmly  in 
Microsoft’s  court.  How  will 
Microsoft  react?  Internet 
Explorer  8  as  currently  of¬ 
fered  in  Beta  2  is  no  match 
for  Chrome’s  underlying 
structure.  IE8,  like  most 
other  browsers,  is  primar¬ 
ily  an  application  and  only 
secondarily  a  platform  for 
Web  applications. 

So  there’s  a  lot  yet  to  un¬ 
fold.  But  Google  Chrome  is 
a  clear  marker  of  things  to 
come.  How  the  IT  vendor 
and  user  communities  re¬ 
act  may  be  more  important 
than  the  product  itself.  ■ 
Scot  Finnie  is  Computer- 
world’s  editor  in  chief.  Tell 
him  what  you  think  at scot_ 
finnie@computerworld.com. 


2  COMPUTERWQRLD  SEPTEMBER  8,  2008 


■  ONLINE  CHATTER 


RESPONSES  TO: 

Vista  May  Still  Have 
Its  Day  -  Just  Like  XP 
(Eventually)  Did 

Aug.  25, 2008 

I’ve  been  in  IT  since  1976;  you  name 
the  crunch,  and  I’ve  got  the  scars. 

I’ve  been  through  this  again  and 
again  with  Microsoft:  Release  a 
half-baked  piece  of  alpha  software 
because  you  have  a  marketing  need. 
And  because  you  were  slipping  de¬ 
livery,  take  out  all  the  interesting, 
real  innovations,  since  they’re  hard 
to  get  right.  Then  make  customers 
suffer  through  a  couple  of  years  of 
beta  testing  to  finally  get  it  to  a  us¬ 
able  form  —  by  which  time  you’re 
ready  to  foist  another  piece  of  ill- 
conceived  and  poorly  implemented 
and  tested  junk  on  them. 

Microsoft  will  get  this  right, 
eventually.  If  there’s  one  thing  they 
do  well,  it’s  beat  a  dead  horse  until 
it  finally  really  DOES  come  to  life. 

Of  course  we  didn’t  want  XP. 

At  the  time  it  was  released,  there 
was  nothing  in  it  for  anyone  who’d 
already  moved  to  Windows  2000, 
except  “protections”  for  Microsoft 
in  its  “Genuine  Advantage”  pro¬ 


gram.  The  fact  that  it  eventually 
did  become  the  most  stable  and 
usable  of  the  MS  desktop  operating 
systems  is  testament  to  their  lock 
on  the  market  and  the  unending 
flood  of  patches,  hotfixes  and  ser¬ 
vice  packs. 

■  Submitted  by:  Dave  Ihnat 

Pretty  much  every  version  of  Win¬ 
dows  has  been  slower  than  the 
previous.  When  software  has  more 
features,  it  is  going  to  need  more  re¬ 
sources.  Pretty  simple.  That’s  why 
you  generally  should  run  Windows 
only  on  hardware  suitable  for  the 
version  you’re  running. 

How  is  a  computer  with  Vista  less 
functional  than  a  computer  with 
XP?  I  use  XP  at  work  and  Vista  at 
home  and  I  get  far  more  done  on 
my  home  PC  because  everything 
is  a  bit  easier.  My  apps  open  more 
quickly  due  to  SuperFetch,  and  I  can 
find  files  more  easily  due  to  the  UI 
tweaks  and  the  search  function. 

Vista  is  great.  It  performs  bril¬ 
liantly  on  my  midrange  PCs. 

■  Submitted  by:  Anonymous 

JOIN  THE  CHATTER!  You ,  too,  can 
comment  directly  on  our  stories, 

at  computerworld.com. 


COMPUTERWORLO 

P.O.  Box  9171, 1  Speen  Street 
Framingham,  MA  01701 
(508)  879-0700 

Computerworld.com 

B  EDITORIAL 

Editorial  Director  Don  Tennant 
Editor  in  Chief  Scot  Finnie 

Executive  Editors  Mitch  Betts, 

Julia  King  (events) 

Managing  Editors  Michele  Lee  DeFilippo 
(production),  Sharon  Machlis  (online), 

Ken  Mingis  (news) 

Design  Director  Stephanie  Faucher 

Features  Editors  Kathleen  Melymuka, 

Valerie  Potter,  Ellen  Fanning  (special  reports), 
Barbara  Krasnoff  (reviews) 

Senior  Editors  Johanna  Ambrosio  (channels), 
Mike  Barton  (new  media),  Joyce  Carpenter 
(blogs  and  projects) 

Senior  News  Editor  Craig  Stedman 
News  Editors  Mike  Bucken,  Marian  Prokop 

National  Correspondents  Gary  Anthes, 
Thomas  Hoffman,  Julia  King,  Robert  L.  Mitchell 

Reporters  Sharon  Gaudin,  Matt  Hamblen, 
Heather  Havenstein,  Gregg  Keizer,  Eric  Lai,  Patrick 
Thibodeau,  Jaikumar  Vijayan,  Todd  R.  Weiss 

Video  Editor  David  Ramel 

Channel  Editors  Johanna  Ambrosio  (servers 
and  data  centers),  Lucas  Mearian  (storage), 

David  Ramel  (networking  and  Internet) 

Assistant  Managing  Editor  Bob  Rawson 
(production) 

Senior  News  Columnist  Frank  Hayes 
Art  Director  April  O’Connor 


Research  Manager  Mari  Keefe 

Senior  Copy  Editors  Eugene  Demaitre, 
Monica  Sambataro 


Find  these  stories  at  computerworld.com/more 


The  First  True  Web  2.0  Browser 

REVIEW:  Google’s  Chrome  uses  simplicity 
and  some  clever  new  features  to  bring  Web 
surfing  into  the  21st  century. 


Video  Games  Are 
Poised  to  Boost 
Corporate  Training 

Games  can  help  compa¬ 
nies  cut  costs,  meet 
the  needs  of  younger 
workers  and  fulfill 
“green  IT”  require¬ 
ments,  according  to 
a  new  report  from 
Forrester  Research. 


When  Linkedln 
Knows  Where  You  Are 

A  convergence  of  social 
networking  and  mobility 
is  under  way  worldwide 
among  teenagers  and 
young  adults.  Soon, 
the  phenomenon  will 
spread  to  corporate 
users  for  business 

purposes,  says  columnist  Mike  Elgan. 


Apricorn’s  160GB 
Aegis  Mini  Hard  Drive 

REVIEW:  Apricorn’s  diminutive 
external  drive  lets  you  carry  160GB 
in  a  shirt  pocket,  with  no  need  for 
a  power  brick.  But  its  small  size 
is  matched  by  a  large  price. 


Copy  Editor  Donna  Sussman 

Associate  Editor,  Community  Ken  Gagnb 
Office  Manager  Linda  Gorgone 

Contributing  Editors  Jamie  Eckle, 

Preston  Gratia,  Tracy  Mayor 

■  CONTACTS 

Phone  numbers,  e-mail  addresses  and 
reporters’  beats  are  available  online  at 
Computerworld.com  (see  Contacts  link 
at  the  bottom  of  the  home  page). 

Letters  to  the  Editor  Send  to  letters® 
computerworld.com.  Include  an  address  and 
phone  number  for  immediate  verification. 

Letters  will  be  edited  for  brevity  and  clarity. 
News  tips  newstips@computerworid.com 
Subscriptions  and  back  issues  (888)  559- 
7327,  cw@omeda.com 
Reprints/permissions  The  YGS  Group, 

(800)  290-5460,  ext.  150,  coiriputerwoiid® 
theygsgroup.com 


DISASTER  RECOVERY 

Gustav  Finds  IT  Execs 
Prepared  for  the  Worst 


Hurricane  gustav 
didn’t  hit  the  Gulf 
Coast  as  hard  as 
had  been  feared  last  week. 
But  some  IT  managers  in 
New  Orleans  said  they 
were  ready  for  whatever 
the  storm  brought,  having 
upgraded  their  disaster 
recovery  capabilities  since 
Katrina  and  Rita  devastated 
the  region  three  years  ago. 

For  instance,  since  2005, 
Loyola  University  has  added 
an  intermediate  disaster- 
recovery  site  at  an  out-of- 
state  location  to  help  main¬ 
tain  communications  and 
keep  a  simplified  version  of 
the  school’s  Web  site  up  and 


running  in  emergencies. 

The  intermediate  site 
adds  a  third  level  of  backup 
capabilities,  complementing 
generators  in  Loyola’s  data 
center  and  hot-site  services 
provided  for  the  university’s 
critical  systems  by  SunGard 
Availability  Services. 

“We  had  a  very  full- 
fledged  disaster  recovery 
plan  prior  to  Katrina,”  said 
Bret  Jacobs,  Loyola’s  execu¬ 
tive  director  of  IT.  But,  he 
added,  the  damage  wrought 
by  that  storm  showed  school 
officials  that  even  more 
preparations  were  needed. 

“We  want  to  have  our  re¬ 
actions  institutionalized  be- 


THE  WEEK  AHEAD 

MONDAY:  Microsoft  launches  its  Hyper-V  hypervisor  and 
other  virtualization  products  at  an  event  in  Bellevue,  Wash. 

MONDAY:  SAP’s  TechEd  2008  (Las  Vegas)  and  Computer- 
world’s  Business  Intelligence  Perspectives  (Phoenix)  open. 

TUESDAY:  Microsoft  plans  to  issue  four  critical  security  fixes. 

TUESDAY:  The  International  Association  of  Outsourcing 
Professionals  holds  a  forum  in  Chicago  on  managing  deals. 


«  Gustav  did  cause  some  flooding 
in  New  Orleans  last  week. 

cause  you  never  know  what 
a  storm  will  do,”  Jacobs  said. 

Digimation  Inc.,  a  devel¬ 
oper  of  3-D  digital  anima¬ 
tion  software  in  St.  Rose, 

La.,  about  10  miles  west  of 
New  Orleans,  was  knocked 
out  of  business  for  a  week 
after  Katrina  struck.  Its 
power  and  Web  site  weren’t 
restored  for  two  weeks. 

Now,  said  Digimation 
President  David  Avgikos,  all 
of  the  company’s  50  or  so 
PCs  and  servers  are  backed 
up  to  a  main  server,  which 
in  turn  is  backed  up  to  a 
1TB  USB-connected  drive 
that  goes  out  the  door  with 
the  last  employee  during  an 
emergency  evacuation. 

And  the  company’s  Web 
site  has  been  farmed  out  to  a 
remote  hosting  provider  far 
from  New  Orleans. 

Tidewater  Inc.,  which 
supports  oil  and  gas  explo¬ 
ration  and  production  com¬ 
panies,  has  set  up  a  “totally 
redundant  IT  system  in  Dal¬ 
las,”  said  Joe  Bennett,  execu¬ 
tive  vice  president  and  chief 
investor  relations  officer. 
“We  can  just  flip  a  switch.” 

Tidewater  has  also  done 
a  lot  of  disaster  recovery 
training  since  2005,  and  it 
held  daily  meetings  of  key 
personnel  as  Gustav  neared 
the  coast.  “Will  this  be  a 
false  alarm?  Possibly,”  Ben¬ 
nett  said.  “But  you  have  to 
be  prepared  for  the  worst.” 

—  Todd  R.  Weiss 


H  The  new  VECD 
licenses  cost  $110 
per  PC  annually, 
or  $23  for  users 
who  want  to  he 
able  to  run  Vista 
on  home  PCs. 


Microsoft  Corp.  last  week 
announced  several  software 
licensing  changes  that  give 
IT  managers  and  end  users 
more  options  for  running 
Windows  Vista  in  desktop 
virtualization  mode. 

Effective  Jan.  1,  Microsoft 
will  expand  its  Vista  Enter¬ 
prise  Centralized  Desktop 
license  to  support  PCs  that 
end  users  buy  themselves 
with  company  stipends. 
Scott  Woodgate,  director  of 
Windows  product  manage¬ 
ment,  said  the  changes  to 
VECD  will  also  enable  IT 
managers  to  deploy  virtual 
Vista  desktops  to  the  PCs 
used  by  contract  workers. 

In  addition,  employees  will 
now  be  able  to  run  Vista  in 
virtual  machines  on  their 
home  PCs,  either  streamed 
from  a  server  or  loaded  from 
a  thumb  drive. 

But  Microsoft  will  continue 
to  require  a  VECD  license 
for  every  system,  no  matter 
how  little  the  virtualization 
option  is  used. 

-  ERIC  LAI 


C0MPUTERW0RLD  SEPTEMBER  8,  2008 


Your  potential.  Our  passion; 

Microsoft 


Deii.com  is  one  of  the  world's  largest  and  most  advanced  e-comr 
sites.  As  a  technology  leader,  Deli  relies  on  Windows  Server*  2 
for  the  flexibility  and  reliability  needed  to  support  a  mission-ci 


m  NEWS  DIGEST 


SECURITY 

Schwarzenegger  Gets 
Softened  Version  of 
Vetoed  Breach  Bill 


ALIFORNIA’S  STATE 
legislature  has  sent 
Gov.  Arnold  Schwarz¬ 
enegger  an  amended  ver¬ 
sion  of  a  closely  watched 
data  breach  bill  that  he 
vetoed  last  October. 

The  Consumer  Data 
Protection  Act,  or  AB 1656, 
would  require  retailers 
and  other  businesses  op¬ 
erating  in  the  state  to  take 
specific  steps  to  prevent 
credit  and  debit  card  data 
from  being  compromised. 
For  instance,  it  would  pro¬ 
hibit  the  storage  of  PINs, 
magnetic-stripe  data  and 
other  information,  even  in 
encrypted  form. 

Retailers  would  also 
have  to  disclose  more 
details  about  breaches  to 
affected  consumers.  But  a 
provision  that  would  have 
required  them  to  reimburse 
financial  institutions  for 
the  cost  of  replacing  com¬ 
promised  cards  has  been 
dropped.  Another  change 
would  let  retailers  retain 
data  needed  to  process 


recurring  payments. 

Melissa  Ameluxen,  a 
lobbyist  for  the  Califor¬ 
nia  Credit  Union  League, 
said  the  CCUL  hopes  the 
removal  of  the  reimburse¬ 
ment  clause  will  go  a  long 
way  toward  ensuring  that 
Schwarzenegger  signs  the 
bill  this  time  around. 

“The  governor’s  office 
gave  us  an  indication  that 
removing  that  part  of  the 


Schwarzenegger  felt  the  origi-  “ 
nal  bill  conflicted  with  private-  5 
sector  data  security  standards.  £ 


HARDWARE 


tom  Chip  Stymied 
>y  Testing  Bottleneck 


A  TESTING  BOTTLENECK  is 
slowing  the  manufacture  of  Intel 
Corp.’s  Atom  processor,  just  as 
computer  makers  are  looking  to 
plug  more  of  the  chips  into  small 
laptops  called  netbooks. 

The  chip  maker’s  chief  finan¬ 
cial  officer,  Stacy  Smith,  first 
disclosed  production  problems 
in  July,  blaming  stronger-than- 


expected  demand  for  the  low- 
end  processor. 

Taipei-based  Asustek  Com¬ 
puter  Inc.  last  month  blamed 
the  production  woes  for  its  de¬ 
cision  to  use  a  much  older  Intel 
chip,  the  900-MHz  Celeron  M 
353,  in  two  models  of  its  popu¬ 
lar  Eee  PC  line. 

An  Intel  spokesman  late  last 


bill  would  help  us  move 
closer”  to  getting  it  signed 
into  law,  Ameluxen  said. 
The  trade  group  is  one  of 
AB  1656’s  chief  proponents. 

The  California  State 
Assembly  approved  the 
amended  bill  by  a  74-1 
margin  on  Aug.  31,  after  the 
state  Senate  had  passed  the 
measure  on  a  34-3  vote  four 
days  earlier. 

A  law  enacted  in  Minne¬ 
sota  in  May  2007  requires 
retailers  that  store  pro¬ 
hibited  data  to  reimburse 
banks  and  credit  unions 
for  card  replacement  costs 
after  breaches  occur. 

But  the  California  bill 
is  the  one  that  retail  and 
banking  trade  groups  have 
really  been  keeping  an 
eye  on.  If  Schwarzeneg¬ 
ger  signs  AB  1656,  many 
analysts  expect  other  states 
will  use  it  as  a  model  for 
similar  statutes. 

That  would  be  unfortu¬ 
nate,  according  to  Gartner 
Inc.  analyst  Avivah  Litan. 
“Governments  should 
stay  out  of  the  security 
business,”  she  said.  “They 
clearly  have  a  role  to  play 
in  [regulating]  breach 
disclosure.  But  it’s  totally 
inappropriate  for  a  state  to 
mandate  security  controls.” 

—  Jaikumar  Vijayan 


Short 

Takes 

In  an  affidavit  filed  in 
federal  court,  former  CA 
Inc,  CEO  Sanjay  Kumar 
implicated  company 
founders  Charles  Wang 
and  Russell  Artzt  and  for¬ 
mer  board  members  Al- 
fonse  D’Amato  and  Lewis 
Ranieri  in  an  accounting 
fraud  scandal  at  the  com¬ 
pany.  Kumar  is  serving  a 
prison  term  on  charges 
related  to  the  scandal. 

Oracle  Corp.  has  agreed 
to  buy  a 

maker  of  software  for 
managing  the  perfor¬ 
mance  of  SOA-based 
applications,  for  an  undis¬ 
closed  sum. 

Open  Text  Corp  plans 
to  purchase  Captaris  Inc., 

a  maker  of  document 
management  and  data 
capture  software,  for 
about  $131  million.  The 
deal  is  set  to  close  by  the 
end  of  the  year. 

Red  Hat  Inc.  has  ac¬ 
quired  Qumranet  Inc.,  for 

$107  million.  Red  Hat  said 
Qumranet’s  embedded 
Kernel  Virtual  Machine 
platform  will  let  its  Enter¬ 
prise  Linux  software  na¬ 
tively  support  virtualized 
Windows  machines  for 
the  first  time. 


month  confirmed 
that  the  testing 
constraint  was 
limiting  produc¬ 
tion,  but  he  declined  to  say 
when  manufacturing  will  meet 
demand. 

Dean  McCarron,  president  of 
Mercury  Research,  noted  that 
testing  and  assembling  raw 
silicon  into  finished  chips  is  a 
labor-intensive  process,  so  it’s 
difficult  to  increase  testing  ca¬ 
pacity  quickly.  “[It]  can  only  be 
done  so  fast,  as  one  has  to  buy 


equipment,  install  it 
and  set  up  the  appro¬ 
priate  factory  lines, 
etc.,”  McCarron  said. 
Also,  he  noted,  Atom 
processors  are  cheaper  than 
most  other  Intel  chips,  and  pri¬ 
ority  in  the  testing  process  goes 
to  more  expensive  models. 

The  bottleneck  may  not  end 
until  2009,  when  Intel  opens 
a  $1  billion  test  and  assembly 
facility  in  Vietnam. 

-SUMNER  LEMON, 
IDG  NEWS  SERVICE 


C0MPUTERW0RID  SEPTEMBER  8,  2008 


NEC’s  advanced  communications 
solutions  put  you  in  charge  when  it 
matters  most. 


Finally,  a  communications  solution  capable  of  providing  up-to-date  patient 
information  whenever  and  wherever  it  is  needed. 

NEC’s  Unified  Communications  provide  a  dynamic  and  realistic  connection  among 
individuals,  devices,  applications,  and  data.  Based  on  a  combination  of  innovative 
technologies  and  advanced  solutions,  its  mobility  and  flexibility  enables  people  to 
experience  greater  efficiency  and  productivity  -  in  any  industry. 

Integrated  IT  and  networking  solutions  like  these  have  made  NEC  a  world  leader, 
and  your  reliable  business  partner. 

Regardless  of  the  communications  solution  your  business  demands,  you  are 
assured  of  one  thing:  NEC.  Empowering  you  through  innovation. 

www.necus.com/necip 


IT  SERVICES  AND  SOFTWARE  NETWORKING  AND  COMPUTING  SEMICONDUCTORS 


IMAGING  AND  DISPLAYS 


Empowered  by  Innovation 


■  NEWS  DIGEST 


ROBOTICS 


U.S.  Army,  iRobot 
Sign  $200M  Pact 


The  u.s.  Army  last  week 
awarded  a  five-year, 
$200  million  contract 
to  iRobot  Corp.  to  supply 
it  with  military  robots  and 
spare  parts  along  with  train¬ 
ing  and  other  services. 

The  pact  was  signed 
about  four  months  after 


Defense  Advanced  Research 
Projects  Agency  awarded 
Tufts  University  in  Medford, 
Mass.,  $3.3  million  in  fund¬ 
ing  to  continue  its  efforts  to 
develop  soft  robots  that  can 
squeeze  into  spaces  a  frac¬ 
tion  of  their  normal  size. 

—  Sharon  Gaudin 


8 

» 

8 

i 

* 

I 

8 

* 

8 

I 

» 

8 

i 

5 

8 

i 

1 

I 

? 

i 

l 

I 

l 

i 

I 

i 

< 

I 

1 

i 

» 

8 

* 

* 

I 

I 

s 

8 

s 

i 

i 

i 

8 

jt 

l 

f 

> 

i 

i 

» 

8 

i 

i 

f 

i 

i 

8 

i 

8 

I 

1 
8 

2 
8 
8 
t 
8 
8 
8 

1 

2 
8 
1 
2 


the  expiration  of  an  earlier 
Army  contract  under  which 
iRobot  supplied  products 
based  on  its  PackBot  robot. 

The  new  contract  covers 
all  iRobot  technologies. 

In  a  statement,  Joe  Dyer, 
president  of  Bedford,  Mass.- 
based  iRobot,  said  the  deal 
shows  that  the  Army  is 
continuing  to  find  ways  to 
use  robotic  technology  on 
the  battlefield,  “allowing 
troops  to  complete  missions 
successfully  while  keeping 
them  at  safe  distances”  from 
dangerous  situations. 

In  recent  months,  vari¬ 
ous  military  agencies  have 
invested  in  robotics  technol¬ 
ogy  for  the  battlefield. 

In  May,  the  U.S.  Army 
Research  Laboratory  in 
Adelphi,  McL,  awarded  a 
$38  million  contract  to  BAE 
Systems  Inc.  to  design  and 
build  microrobots  inspired 
by  birds  and  insects. 

And  last  month,  the  U.S. 


Global 

Dispatches 

U.K.  Airport  Tests 
Facial  Recognition 

MANCHESTER,  England  - 
The  Manchester  Airport  last 
month  started  testing  a  facial 
recognition  system  that  was 
installed  as  part  of  the  £1.2  bil¬ 
lion  ($2.1  billion  U.S.)  U.K. 
e-Borders  program,  which  is 
designed  to  better  control  entry 
into  the  country. 

The  new  system  is  based  on 
technology  from  Vision-Box 
Co.  in  Lisbon  and  was  installed 
by  Fujitsu  Services  in  London. 
Officials  expect  it  to  tighten 
border  security  and  speed  up 
immigration  processing  times. 

The  system  will  compare 
the  faces  of  U.K.  and  European 
Union  travelers  to  their  bio¬ 
metric  passports.  It  will  also 


BETWEEN  THE  LINES  By  John  Klossner 


frChram1 


Alcatel-Lucent  tapped 
Ben  Verwaayen,  a  Dutch 
national  who  was  CEO  of 
until  June  1, 
to  be  its  CEO,  and  it  named 
Philippe  Camus,  a  French 
native  who  lives  in  the  U.S., 
chairman.  The  positions  had 
been  open  since  July  29. 

added  a  You¬ 


Tube-like  video-sharing  tool 
to  Google  Apps  Premier  Edi¬ 
tion,  its  fee-based  suite  of 
online  applications. 

10  YEARS  AGO:  Google  was 
incorporated  by  Stanford 
graduate  stu¬ 
dents  Larry  Page  and  Ser¬ 
gey  Brin  after  they  raised 
$1  million  in  start-up  funds. 


enable  people  with  electronic 
passports  to  move  through  im¬ 
migration  on  a  fast  track  with 
no  prior  registration. 

A  U.K.  mandate  requires 
that  everyone  traveling  into  and 
out  of  the  country  be  checked 
against  immigration  and  secu¬ 
rity  watch  lists  by  2014. 
Computerworld  U.K.  staff 

Sony  Recalls 
438,000  Laptops 

TOKYO  -  Sony  Corp.  last  week 
recalled  438,000  Vaio  TZ 
laptops  because  of  a  possible 
manufacturing  defect  that  may 
cause  them  to  overheat. 

The  U.S.  Consumer  Product 
Safety  Commission  said  some 
of  the  computers  have  been 
found  to  have  a  problem  with 
wiring  near  the  hinge  that  could 
lead  to  short-circuiting  and 
overheating. 

One  person  has  suffered  a 
minor  burn  as  a  result  of  the 


defect,  and  Sony  has  received 
15  other  reports  of  overheating 
computers,  the  Product  Safety 
Commission  said. 

The  Vaio  recall  comes  about 
two  years  after  Sony  recalled 
millions  of  its  laptop  batteries 
because  of  overheating  issues. 
Peter  Sayer, 

IDG  News  Service 

BRIEFLY  NOTED 

Mphasis  Ltd.,  an  outsourcer 
based  in  Bangalore,  last  week 
announced  plans  to  open  a 
new  software  development  and 
services  facility  in  Hyderbad, 
India,  that  will  employ  1,000 
people  within  a  year.  The 
company  currently  has  about 
28,000  workers. 

John  Ribiero, 

IDG  News  i 


COMPUTERWORLD  SEPTEMBER  8,  2008 


NEWS  ANALYSIS  ■ 


Google  Adds 
A  Weapon  in 
Its  Battle  to 
Kill  Windows 

Chrome  browser  promises  to 
provide  a  significant  perfor¬ 
mance  boost  to  online  apps. 

By  Heather  Havenstein 


Last  WEEK’S  unveil¬ 
ing  of  a  new  browser 
is  the  latest  in  a 
series  of  moves  by 
Google  Inc.  to  rid  the  world 
of  Microsoft  Windows,  ac¬ 
cording  to  analysts. 

In  fact,  said  Matt  Rosoff, 
an  analyst  at  Directions  on 
Microsoft  in  Kirkland,  Wash., 
the  new  Chrome  browser 
could  be  the  key  component 
of  Google’s  plan  to  convince 
consumers  and  business 
users  to  replace  Windows- 
based  software  with  hosted 
Web  applications. 

“This  is  the  potential 
threat  that  Microsoft  has 
been  worried  about  since 
the  1990s,”  Rosoff  said. 

“This  is  Google  trying  to 
really  push  applications  to 
the  Web  and  make  that  the 
way  people  do  computing.” 

Google  began  offering 
a  beta  version  of  the  new 
open-source  browser  on  its 
Web  site  last  week. 

Chrome  includes  a  new 
high-performance  JavaScript 
engine  and  Google  Gears, 
which  will  let  users  store  and 
access  Web  applications  off¬ 
line.  The  browser  is  powered 
by  the  WebKit  open-source 


rendering  engine,  also  used 
in  Apple  Inc.’s  Safari  brows¬ 
er,  and  includes  unspecified 
Firefox  components. 

At  a  press  briefing,  Sergey 
Brin,  co-founder  and  tech¬ 
nology  president  at  Google, 
said  he  expects  Chrome  to 
serve  as  a  strong  vehicle  for 
running  Web  applications. 

“I  wouldn’t  call  Chrome  the 
OS  of  Web  apps,”  Brin  said. 
“It’s  a  very  basic,  fast  engine 
to  run  Web  apps.” 

Google  likely  won’t  posi¬ 
tion  Chrome  simply  as  a 
competitor  to  established 


browsers  from  vendors  like 
Microsoft,  Mozilla,  Apple 
and  Opera  Software,  noted 
Ray  Valdes,  an  analyst  at 
Gartner  Inc. 

“It’s  about  the  Web  apps 
battle,”  Valdes  said.  “It’s 
about  having  a  platform  that 
will  support  the  next  gen¬ 
eration  of  Web  apps.” 

Google  spent  two  years 
making  sure  its  system  could 
overcome  the  growing  inabil¬ 
ity  of  current  technologies  to 
run  new  online  applications. 
It  was  “definitely  a  strategic 
initiative,”  Valdes  said. 

Earlier  steps  in  Google’s 
long-term  plan  to  kill  Win¬ 
dows  include  the  2006 
launch  of  the  Google  Apps 
hosted  applications  suite. 
That  offering  includes  the 
Google  Docs  collaboration 
tool,  Gmail  e-mail  software, 
Google  Calendar,  the  Talk 
instant  messaging  and 
voice-over-IP  application, 
and  the  Sites  wiki  service. 

Google  is  also  expected  to 
soon  unveil  an  online  stor¬ 
age  offering. 

Corporate  IT  managers 
have  so  far  been  unenthusi- 
astic  about  replacing  pack¬ 
aged  software  with  Google’s 
Web-based  offerings.  Robert 
Ford,  CIO  at  Virgin  Enter¬ 
tainment  Group  Inc.,  said 
Chrome  likely  won’t  change 


C  tr  I 


*■  D*  Jb' 


$  GaogieWaos  &  GooeteBookSewch  «e*  eBay 

Most  visited 

Q  Bloqgw;  Create  your  free  bloo  3  Crngjj:  £msil  ftQiP  SgPfltg 


P'taaa  vm  Mums 


£3  Othes  book't'arte 

Goegle 

Chrome  ftc’x 


l0Soggfeyj|it  history 

Recent  bookmarks 

Si 


Recently  closed  tabs 


S  Gooqie  Maos 


3  Goods  Book  Search 


—  1 

—  *■ — 

1 11213 

1198  1 

IH'T 

,83  a 


Google’s  Chrome  beta  had  garnered  a  1%  share  of  the  browser 
market  within  24  hours  of  its  release  last  Tuesday. 


J 


that  view,  at  least  at  Virgin. 

Although  Chrome  is  im¬ 
pressive,  “there  would  have 
to  be  astronomical  perfor¬ 
mance  improvements  for  us 
to  switch,”  Ford  said. 

He  noted  that  IE  is  the 
Los  Angeles-based  retailer’s 
corporate  standard,  and 
developers  there  are  expert 
in  Microsoft  .Net-based 
technologies.  “I  don’t  see 
any  reason  to  challenge  our 
IE  standard,”  Ford  said.  “I’d 
have  to  make  sure  Chrome 
worked  well  with  all  of  our 
other  apps.  What  is  the  busi¬ 
ness  value  in  that?” 

In  a  statement,  Dean 
Hachamovitch,  IE  general 
manager  at  Microsoft,  said 
the  company  expects  most 
users  to  continue  turning 
to  Internet  Explorer,  which 
holds  about  72%  of  the 
browser  market,  according 
to  Net  Applications  Inc., 
an  Aliso  Viejo,  Calif.-based 
Web  metrics  research  firm. 

Sheri  McLeish,  an  analyst 
at  Forrester  Research  Inc., 
said  that  Chrome  “is  not 
compelling  enough  to  erode 
Microsoft’s  dominance.  Too 
many  IT  shops  are  comfort¬ 
able  with  IE.” 

McLeish  noted  that  per¬ 
suading  users  to  switch 
browsers  is  a  difficult  task 
for  any  vendor.  Even  Micro¬ 
soft  has  faced  challenges 
getting  users  to  upgrade  to 
new  versions  of  IE,  she  said. 

Rosoff  added  that  Google 
also  faces  a  significant  chal¬ 
lenge  in  finding  ways  to  dis¬ 
tribute  the  new  browser. 

“Google  is  a  powerful 
brand,  but  they  do  need  a 
way  to  distribute  the  brows¬ 
er,”  he  noted.  PC  makers,  an 
obvious  potential  distribu¬ 
tion  path,  may  be  wary  of 
replacing  Windows  with 
Web-based  applications.  ■ 
Eric  Lai,  Gregg  Keizer  and 
the  IDG  News  Services’  Juan 
Carlos  Perez  contributed  to 
this  story. 


SEPTEMBER  8,  2008  C0MPUTERW0RLD  9 


Put  Teeth 
Into  HIPAA 

Enforcement 


Three  years  after  the  federal  law’s  rules 
on  securing  health  care  data  took  effect, 
HHS  has  issued  its  first  ‘corrective 
action  plan.’  By  Jaikumar  Vijayan 


A  DATA  SECURITY  audit 

that  the  U.S.  Department 
of  Health  and  Human 
Services  conducted  at 
Piedmont  Hospital  in 
Atlanta  last  year  was  widely  viewed 
within  the  health  care  industry  as  a 
harbinger  of  further  actions  by  the  fed¬ 
eral  government  to  enforce  HIPAA’s 
security  and  privacy  rules. 

Eighteen  months  after  HHS  quietly 
began  the  Piedmont  audit,  there  hasn’t 
been  much  evidence  of  stepped-up  en¬ 
forcement.  But  now  a  stringent  “reso¬ 
lution  agreement”  signed  in  July  by  the 
agency  and  Seattle-based  Providence 
Health  &  Services  is  generating  the 
same  kind  of  buzz  among  health  care 
providers  that  the  Piedmont  audit  did. 

On  July  15,  Providence  agreed  to 
adopt  a  so-called  corrective  action 
plan  (CAP)  and  pay  $100,000  to  settle 
what  HHS  described  as  “potential 
violations”  of  the  Health  Insurance 
Portability  and  Accountability  Act’s 
requirements  for  safeguarding  elec¬ 
tronic  patient  data. 

The  resolution  agreement  — 
the  first  of  its  kind  under  HIPAA 
—  stemmed  from  the  loss  or  theft  of 
laptops,  optical  discs  and  backup  tapes 
containing  the  unencrypted  medical 
records  of  more  than  386,000  Provi¬ 
dence  patients.  On  several  occasions 
in  2005  and  2006,  equipment  was 
reported  missing  after  workers  took  it 
out  of  the  office  with  them. 

Under  the  CAP,  Providence  has  to 
revamp  its  security  policies  to  include 
physical  protections  for  portable 
devices  and  for  the  off-site  transport 
and  storage  of  backup  media.  It  also  is 
required  to  implement  technical  safe¬ 
guards,  such  as  encryption  and  pass¬ 
word  protection.  And  the  not-for-profit 
health  system,  which  has  operations 
in  five  western  states,  must  conduct 
random  compliance  audits  and  submit 
compliance  reports  to  HHS  for  the 
next  three  years  (see  box,  next  page). 

In  addition,  the  agreement  calls  for 
Providence’s  chief  information  secu¬ 
rity  officer  to  personally  validate  that 
all  required  policies  have  been  put 
in  place  and  that  all  employees  have 
been  trained  on  adhering  to  them.  The 
CISO  also  has  to  attest  that  all  backup 
media  and  portable  devices  contain¬ 
ing  health  information  protected  by 


a  C0MPUTERW0RLD  SEPTEMBER  8,  2008 


HIPAA  are  properly  secured. 

Significantly,  the  CAP  precludes 
Providence  Health  from  contesting 
the  validity  of  or  appealing  any  of  its 
obligations  under  the  agreement.  The 
settlement  is  getting  considerable  atten¬ 
tion  within  the  health  care  industry  be¬ 
cause  of  the  tough  terms  and  conditions 
that  the  deal  imposed  on  the  provider. 

“The  CAP  gives  us  some  indica¬ 
tion  that  the  bar  is  being  raised  when 
it  comes  to  HIPAA  compliance,”  said 
Lisa  Gallagher,  director  of  privacy  and 
security  at  the  Healthcare  Informa¬ 
tion  and  Management  Systems  Society 
(HIMSS)  in  Chicago.  “This  is  a  fairly 
serious  corrective  action  plan.” 

Gallagher  added  that  the  deal  with 
Providence  sends  a  clear  message  to 
other  health  care  providers  that  HHS 
is  finally  cracking  down  on  HIPAA 
violators,  after  having  been  accused  of 
lax  enforcement  in  the  past. 

The  harder  line  is  in  keeping  with 
an  announcement  in  January  that  the 
Centers  for  Medicare  &  Medicaid  Ser¬ 
vices  (CMS),  the  HHS  unit  responsible 
for  administering  the  HIPAA  security 
rules,  had  hired  Pricewaterhouse- 
Coopers  to  conduct  audits  on  its 
behalf.  At  the  time,  the  CMS  said  it 
planned  to  do  10  to  20  audits  this  year 
at  organizations  that  had  been  the 
target  of  complaints  about  their  data 
security  practices. 

According  to  Gallagher,  the  CMS  is 
expected  to  release  findings  from  those 
audits  early  next  year.  It  also  plans  to 
highlight  violation  trends  and  provide 
guidance  on  the  biggest  problems  that 
health  care  providers  are  having  in 
implementing  the  controls  required  by 
HIPAA.  “As  far  as  I  know,  they  are  un¬ 
der  way  with  these  audits,”  she  said. 

Gallagher  also  expects  the  CMS  to 
start  working  more  closely  on  enforce¬ 
ment  with  the  HHS  Office  of  Civil 
Rights,  which  administers  the  data 
privacy  rules  set  by  HIPAA. 

As  of  press  time,  the  CMS  had  yet  to 
respond  to  questions  that  were  sent  via 
e-mail,  as  an  agency  spokesman  had 
requested.  Providence  officials  also 
asked  that  questions  be  sent  via  e-mail 
but  also  hadn’t  responded. 

Peter  MacKoul,  president  of  HIPAA 
Solutions  LC,  a  consulting  firm  in  Sug¬ 
ar  Land,  Texas,  agreed  with  Gallagher 
that  the  Providence  settlement  was  a 


dramatic  example  of  the  potential  con¬ 
sequences  of  HIPAA  violations. 

“If  you  look  at  what  they’re  being 
forced  to  do,  it’s  scary,”  he  said.  “They 
have  lost  their  ability  to  contest  any¬ 
thing;  there’s  no  way  of  getting  out  of 
this  agreement.  And  this  is  the  best 
deal  they  could  get.” 

MacKoul  added  that  while  Provi¬ 
dence  was  audited  for  data  security 
violations,  many  of  the  corrective  ac¬ 
tions  it  is  being  required  to  implement 
fall  into  the  privacy  realm,  showing 
that  HHS  is  making  little  distinction 
between  privacy  and  security  for  com¬ 
pliance  purposes. 


C0RRECT1V! 


The  security  action  items  that  Provi¬ 
dence  Health  &  Services  agreed  to 
include  the  following: 

Revise  policies  and  procedures  for 
safeguarding  patient  data  while  it  is 
stored  at  or  being  transported  to  off¬ 
site  facilities. 

Train  all  workers  on  security  policies 
and  submit  proof  to  HHS  that  the  train¬ 
ing  has  been  completed. 

*  Update  policies  as  needed,  but  at 
least  on  an  annual  basis. 

i  Ensure  that  a  security  risk  assess¬ 
ment  and  management  plan  and  a  data 
breach  notification  policy  are  in  place. 

«!  Conduct  reviews  that  include  unan¬ 
nounced  audits,  spot  checks  and  site 
visits  at  company  facilities. 

"  SOURCE,  U.S  .  6 f  P  ART  M  I N  T  O-f  -  .  .  A.  .  /•/. 

.  HEALTH  A.NO  H  U  MAH  S£'RV  |t  ERR  '  "  •  ’  "  ./ 


And  based  on  the  terms  of  the  CAP, 
organizations  that  have  to  comply 
with  HIPAA  shouldn’t  be  lulled  into 
complacency  by  the  previous  lack  of 
enforcement,  MacKoul  warned.  “If  I 
were  a  covered  entity,  I  wouldn’t  want 
to  roll  the  dice  and  get  caught  up  in 
something  like  this,”  he  noted. 

The  resolution  agreement  does 
appear  to  be  a  belated  attempt  by  HHS 
to  get  the  health  care  industry  to  take 
HIPAA  more  seriously,  said  Chris 
Apgar,  president  of  consulting  firm 
Apgar  &  Associates  LLC  in  Portland, 
Ore.  “I  think  it’s  about  time  they  used 
somebody  as  an  example,”  he  said. 

Even  so,  it’s  unrealistic  to  expect  a 


large  increase  in  the  number  of  HIPAA 
enforcement  actions  in  the  near  term, 
according  to  Apgar  and  other  analysts. 
Such  actions  are  triggered  only  when 
complaints  are  lodged  against  organi¬ 
zations.  HHS  has  no  HIPAA  cops  who 
are  actively  looking  for  violations,  and 
health  care  providers  aren’t  required  to 
report  internal  violations  themselves. 

Also,  neither  the  CMS  nor  the  HHS 
Office  of  Civil  Rights  has  anywhere 
near  the  resources  or  the  funding 
needed  to  investigate  all  of  the  com¬ 
plaints  that  are  filed.  As  a  result, 
examples  such  as  the  settlement  deal 
with  Providence  will  likely  continue 
to  be  more  the  exception  than  the  rule, 
Apgar  said. 

In  fact,  one  of  the  primary  reasons 
why  Providence  was  investigated  in  the 
first  place  no  doubt  was  the  publicity 
generated  by  the  incidents  involving 
lost  IT  equipment,  said  Randy  Yates, 
director  of  security  at  Memorial  Her¬ 
mann  Healthcare  System  in  Houston. 

“Once  something  that  large  hits  the 
media,  the  government  is  bound  to  do 
something,”  Yates  said.  “[The  CAP] 
puts  out  a  message  that  says,  ‘We  see 
this  thing,  and  we  don’t  like  it.’  ” 

Often,  enforcement  actions  are  im¬ 
portant  because  they  get  the  attention 
not  just  of  those  in  charge  of  imple¬ 
menting  privacy  and  security  policies, 
but  also  of  those  who  control  the  purse 
strings  within  organizations.  Last  year, 
for  instance,  the  audit  at  Piedmont 
Hospital  contributed  to  the  approval  of 
a  $1.3  million  budget  item  for  data  en¬ 
cryption  at  Memorial  Hermann. 

But  if  the  investigations  are  as  spo¬ 
radic  as  they  have  been  in  the  past,  the 
buzz  generated  will  fade  away  quickly, 
said  Christopher  Paidhrin,  IT  security 
officer  at  ACS  Healthcare  Solutions,  a 
Dearborn,  Mich.-based  unit  of  Affili¬ 
ated  Computer  Services  Inc. 

Paidhrin  noted  that  the  Piedmont 
audit  last  year  initially  raised  a  con¬ 
siderable  amount  of  concern  among 
health  care  providers.  But  most  of  that 
concern  eventually  melted  away  when 
the  expected  increase  in  enforcement 
actions  failed  to  materialize.  The  same 
thing  will  likely  happen  in  the  after- 
math  of  the  Providence  Health  settle¬ 
ment,  he  said  —  unless  HHS  takes 
additional  actions  elsewhere  and  publi¬ 
cizes  them  to  the  same  extent.  ** 


SEPTEMBER  8, 2008  COMPUTERWQRLD  11 


■  THE  GRILL 

Norman  Matloff 

The  longtime  H-1B  nemesis  talks 
about  what’s  wrong  with  the 
program,  why  it’s  tough  to  be  40 
in  IT,  and  what  he  tells  computer 
science  students. 


NAME:  Norman  Matloff 

TITLE:  Professor  of 
computer  science 

ORGANIZATION:  University 
of  California,  Davis 

FAVORITE  BOOK:  “Any 
kind  of  biography.  One 
memorable  book:  Serious: 
The  Autobiography,  by  John 
McEnroe.” 


PET  PEEVE  (TECHNOLOGY 
EDITION):  “Everybody  ought  to 
use  Linux.”  (Windows  gets  in 
his  way.) 

PET  PEEVE  (PEOPLE  EDITION): 
“People  who  aren’t  thinking. 
They  follow  like  sheep.” 


When  Norman  Matloff  warned  Congress 
about  the  H-1B  visa  program  in  1998,  he 
was  one  of  the  first  to  do  so.  His  testi¬ 
mony,  titled,  “Debunking  the  Myth  of  a 
Desperate  Software  Labor  Shortage,” 
helped  frame  the  national  debate  over  the 
H-1B  visa.  He  remains  the  leading  critic  of 
the  program,  which  has  heavy  support  in 
Congress. 

How  did  you  get  involved  in  the  H-1B  de¬ 
bate?  Even  in  1998,  there  were  severe 
problems  that  were  masked  by  all 
the  hoopla  about  the  dot-com  boom. 
There  were  a  number  of  people  who 
just  weren’t  able  to  get  work,  and  these 
were  generally  people  who  were  over 
40,  many  well  qualified  in  the  classical 
sense  —  years  of  significant  experience. 
It  was  clear  that  what  the  industry  want¬ 
ed  was  cheap  labor.  One  of  the  ways  to 
get  cheap  labor  is  to  hire  young,  and  if 
you  run  out  of  young  people  to  hire  that 
are  U.S.  citizens  and  permanent  resi¬ 
dents,  you  turn  to  hiring  young  foreign 
people.  Almost  all  the  H-lBs  are  young. 

What  drew  your  attention  to  the  situa¬ 
tion?  I’m  very  deeply  immersed  in  the 
Chinese  immigrant  community  [Mat¬ 
loff  speaks  Mandarin,  and  his  wife  is 
an  immigrant  from  Hong  Kong]  and 
saw  a  lot  of  people  that  were  hired  on 
H-l  visas  [the  predecessor  of  the  H-1B 
program]  who  were  not  really  good.  So 
I  had  suspicions. 

Continued  on  page  14 


?  C0MPUTERW0RLD  SEPTEMBER  8,  2008 


■HI 


life  . 


You  No  Longer  Have  To 

Many  businesses  limit  their  options  when  it  comes 
to  networking.  But  with  HP  ProCurve,  you  can  open 
a  whole  new  range  of  possibilities.  With  secure  and 


a bW 


reliable  solutions  that  adapt  to  the  changing  needs 
of  your  organization,  you  now  have  the  opportunity  to 
optimize  your  network  for  business  results. 


Network  of  Choice 

You  have  a  choice  at  ProCurve.com/Choice 


ProCurve 


Networking  by  HP 


©  2008  Hewlett  Packard  Development  Company,  L.P. 


m  THE  GRILL  !  NORMAN  MATLOFF 


Min  many  cases, 
the  parents  in 
Silicon  Valley 
are  encourag¬ 
ing  their  kids  not  to  go  into 
the  [IT]  field  because  they 
know  what’s  going  on. 


Continued  from  page  12 

Don’t  your  connections  with  the  immigrant 
community  put  pressure  on  you  to  favor 
more  relaxed  policies  on  immigration? 

People  who  are  immigrants  are  harmed 
by  H-lBs  just  like  the  natives  are,  even 
the  ones  who  are  originally  H-lBs.  The 
minute  they  get  a  green  card,  they  are 
somewhat  less  employable,  and  when 
they  hit  age  35  and  40,  they  are  a  lot  less 
employable,  just  like  the  natives  are. 

I  will  assume  you  have  some  foreign  stu¬ 
dents  in  your  computer  science  classes.  At 

the  undergraduate  level,  the  number  of 
foreign  students  is  small.  The  graduate 
level  is  different.  This  was  all  planned 
for  by  the  National  Science  Foundation. 
Their  concern  was  that  Ph.D.  salaries 
were  too  high,  and  they  said  that  they 
were  going  to  remedy  it  by  bringing  in 
a  lot  of  foreign  students.  Swelling  the 
labor  pool  will  reduce  the  salaries  or 


reduce  the  growth  in  salaries,  and  that 
was  at  the  same  time  NSF  was  pushing 
Congress  to  enact  the  H-1B  program. 
NSF  also  said  at  the  time  that  by  limiting 
salaries,  Americans  would  be  dissuaded 
from  pursing  graduate  degrees  and,  of 
course,  that’s  exactly  what  happened.  So 
now  you  see  only  50%  of  the  Ph.D.s  in 
computer  science  go  to  Americans. 

How  do  you  reconcile  your  views  with  your 
own  personal  interactions  with  foreign 
students  completing  graduate  programs 
at  your  university?  I  don’t  think  there  is 
anything  to  reconcile,  for  two  reasons. 
Why  should  I  blame  them  for  wanting 
to  do  this?  It’s  attractive  to  them.  Our 
national  policy  has  made  it  available 
to  them.  There  is  no  reason  to  hold  it 
against  them.  The  second  reason  is,  I 
have  always  been  strongly  in  favor  of 
rolling  out  the  immigration  red  carpet 
for  people  who  are  the  so-called  best 
and  the  brightest  —  although  I  definite¬ 
ly  do  not  say  that  anybody  who  has  a 
Ph.D.  is  the  best  and  the  brightest.  And 
for  the  ones  who  are,  I’ve  gone  out  of 
my  way  to  help  them  get  jobs  in  Silicon 
Valley  and  elsewhere. 

But  how  do  you  sort  it  out?  How  do  you 
determine  who  are  the  best  and  the 
brightest?  A  lot  of  people  are  not  aware 
of  this,  but  there  is  already  a  policy. 

For  temporary  visas,  there  is  the  visa 
named  0-1  [for  aliens  of  extraordinary 
ability  and  achievement],  and  for  green 
cards  you  have  the  three  levels  [with 
EB-1  designated  for  those  demonstrat¬ 
ing  the  most  talent  in  a  particular  area]. 

What  would  the  H-1B  program  look  like  in 
your  model?  It  would  be  a  lot  smaller, 
way  smaller  —  and  the  criteria  for  qual¬ 
ifying  would  look  similar  to  the  EB-1. 

The  presidential  candidates  all  seem  to 
support  the  H-1B  program.  And  Congress 
would  have  increased  the  cap  last  year, 
had  it  reached  an  agreement  on  immigra¬ 
tion  reform.  It  seems  as  if  you  are  fighting 
a  losing  battle.  How  would  you  define 
success  at  this  point?  There  are  degrees 
of  success.  A  glass-is-half-full  point  of 
view  would  be,  “Gee,  we’ve  held  them 
off  this  long  [from  a  cap  increase];  that’s 
pretty  good.”  It’s  a  success  of  a  sort.  On 
the  other  extreme,  you  restore  H-1B  to 
the  original  intention  of  just  bringing 


in  the  best  and  the  brightest.  But  what 
would  be  a  realistic  goal?  A  realistic 
goal  is  part  of  the  Durbin-Grassley  Act 
[the  U.S.  Senate’s  H-1B  and  L-l  Visa 
Fraud  and  Abuse  Prevention  Act,  spon¬ 
sored  by  Sens.  Dick  Durbin  (D-Ill.)  and 
Chuck  Grassley  (R-Iowa)].  By  far  the 
most  important  part  of  the  bill  is  to 
redefine  prevailing  wage.  Currently,  the 
employers  by  statute  are  required  to 
pay  prevailing  wage,  but  the  definition 
of  prevailing  wage  is  full  of  loopholes. 
The  Dubin/Grassley  bill  would  fix 
that  by  setting  a  definition  of  prevail¬ 
ing  wage  that  really  would  make  it  the 
market  wage. 

The  second  most  important  aspect  of 
the  bill  is  it  would  take  the  current  re¬ 
strictions  on  H-lB-dependent  employ¬ 
ers  [those  that  have  a  significant  num¬ 
ber  of  H-1B  workers  on  staff]  and  make 
them  applicable  to  all  H-1B  employers. 

There  are  several  restrictions  on 
H-lB-dependent  employers.  The  one 
that  would  be  the  most  important 
would  be  an  anti-layoff  provision. 
H-lB-dependent  companies  are  not  al¬ 
lowed  to  hire  any  H-1B  workers  within 
90  days  of  a  layoff,  either  prior  or  after¬ 
ward.  That  restriction  under  the  Grass- 
ley/Durbin  bill  would  apply  to  all  H-1B 
employers,  and  that  would  be  some¬ 
thing  that  would  be  really  worth  hav¬ 
ing.  Employers  would  also  be  required 
to  try  to  hire  Americans  first.  The  im¬ 
pact  would  be  giant.  They  wouldn’t  be 
able  hire  H-lBs  as  cheap  labor. 

You  have  written  that  computer  science 
departments  must  be  honest  with  stu¬ 
dents  regarding  career  opportunities  in 
the  field.  What  do  you  tell  students  today? 

I  am  chair  of  our  undergraduate  cur¬ 
riculum  committee,  and  every  year  I 
give  a  presentation  to  high  school  se¬ 
niors  and  their  parents.  I  tell  them  that 
things  are  fairly  good  for  new  gradu¬ 
ates  right  now,  [though]  they  aren’t 
nearly  as  good  as  they  were  in  the  late 
1990s.  But  once  you  are  out  10  years 
or  so,  then  you’ve  got  to  be  nimble.  It’s 
much  harder  to  find  work  after  you 
have  been  in  the  field  for  10  years  or 
so.  A  lot  of  the  parents  themselves  are 
engineers.  In  many  cases,  the  parents 
in  Silicon  Valley  are  encouraging  their 
kids  not  to  go  into  the  field  because 
they  know  what’s  going  on. 

—  Interview  by  Patrick  Thibodeau 


COMPUTERWORLD  SEPTEMBER  8,  2008 


■  OPINION 

Sharon  Machlis 

Let’s  Impeach 
E-voting 


WERE  SOFTWARE  PATCHES  that  didn’t 

fix  problems  but  instead  changed  results 
applied  to  electronic  voting  machines  in  two 
Georgia  counties?  Were  the  patches  applied 
at  the  instruction  of  a  top  Diebold  executive,  without  informing 
local  election  officials? 


This  charge  has  been 
leveled  several  times  since 
a  rather  surprising  election 
in  which  two  Democratic 
candidates  had  comfort¬ 
able  leads  in  polls  just  be¬ 
fore  Election  Day  yet  lost 
by  substantial  margins. 

Of  course,  there’s  a  strong 
correlation  between  your 
degree  of  suspicion  of  those 
results  and  which  party  you 
support.  But  we  should  all 
be  frightened  if  there’s  no 
way  to  prove  that  tampering 
didn’t  occur.  And  when  vot¬ 
ing  machines  are  electronic, 
paperless  and  proprietary, 
it’s  all  but  impossible  to  do  a 
recount  or  check  for  errors 
in  a  way  that  can  uncover  a 
malicious  hack  (or  honest 
mistake).  Tech  professionals 
across  the  political  spec¬ 
trum  should  be  unhappy 
with  that  kind  of  system. 

Election  consultant 
Chris  Hood  told  Rolling 
Stone  magazine  that  he 
was  working  for  Diebold 
in  Georgia  in  2002  when 
the  head  of  the  company’s 
election  division  arrived 


to  distribute  a  patch  to 
workers.  That  code  was 
applied  to  only  about  5,000 
machines  in  two  counties. 
Hood  says  it  was  an  unau¬ 
thorized  patch  that  was  kept 
hidden  from  state  officials. 
(Diebold  says  the  state  ap¬ 
proved  the  update,  although 
state  officials  have  since 
asked  for  more  informa¬ 
tion  on  the  patch’s  effect.) 

The  Georgia  allegations 
are  disturbing  but,  sadly, 
not  unique.  An  attorney  and 
IT  security  consultant  last 
month  cited  that  incident  to 
renew  challenges  to  2004 
Ohio  elections,  which  had 
a  similar  mix  of  paperless 
Diebold  machines  and  sta¬ 
tistically  curious  results. 

In  Alabama,  questions 
linger  about  a  supposed 

M  There’s  a  simple 
answer  to  all  of 
this;  paper  ballots 
that  are  scanned 
and  counted  by 
machines. 


“glitch”  that  caused  of¬ 
ficials  to  change  the  winner 
of  the  governor’s  race  six 
years  ago;  a  research  paper 
presented  to  the  Alabama 
Political  Science  Asso¬ 
ciation  later  described  the 
new,  changed  results  as  sta¬ 
tistically  “anomalous”  and 
outlined  a  possible  scenario 
of  vote-counting  fraud. 

Paper  isn’t  perfect,  as 
Florida’s  “hanging  chad” 
fiasco  of  2000  painfully 
demonstrated.  And  paper 
systems  aren’t  necessarily 
100%  secure;  it’s  certainly 
possible  to  destroy  or  alter 
paper  ballots  locally.  But 
unprecedented  statewide 
and  even  nationwide 
tampering  with  elections 
is  theoretically  possible 
when  a  company  controls 
the  counting  devices  with¬ 
out  the  independent  verifi¬ 
cation  that  paper  receipts 
provide. 

Without  paper  ballots, 
there’s  no  way  for  candi¬ 
dates  —  or  voters  —  to 
contest  a  suspicious  result, 
since  each  person’s  action 


J'S  C0MPUTERW0RLD  SEPTEMBER  8,  2008 

( 


must  remain  anonymous. 

There’s  a  simple  answer 
to  all  of  this:  paper  bal¬ 
lots  that  are  scanned  and 
counted  by  machines.  Au¬ 
tomated  ballot  counting  is 
much  quicker  than  manual  j 
counting,  but  retallying  by 
hand  is  still  possible  should  ! 
the  results  be  doubted. 

These  systems  have  the 
added  benefit  of  being  able  \ 

to  easily  process  large 
numbers  of  voters  when 
turnout  is  unusually  high, 
preventing  hours-long 
waits  at  polls  due  to  a  lack 
of  functioning  machines. 

It’s  a  lot  easier  to  ramp  up 
for  an  unexpected  crowd  if  « 
all  you  have  to  do  is  hand 
out  more  paper  ballots. 

If  election  officials  insist  \ 
on  an  electronic  system, 
they  should  require  a  pa¬ 
per  printout  that  voters 
can  verify  and  deposit  in  a  J 
secure  storage  area.  Those  { 
paper  ballots  can  then  be 
counted  by  hand  if  need 
be,  and  electronic  results 
can  be  confirmed. 

Those  of  us  who  vote 
on  paperless  machines, 
whether  with  touch  screens  ! 
or  levers,  can  never  be  con-  * 
fident  that  our  votes  will 
be  properly  submitted,  reg-  j 
istered  and  counted.  That 
leaves  our  elections  under 
perpetual  suspicion,  which¬ 
ever  candidates  prevail. 

It’s  time  to  outlaw  any 
voting  machine  that  doesn’t  ! 
offer  the  possibility  of  a 
paper-based  recount.  ■ 

Sharon  Machlis  is  the  man¬ 
aging  editor  of  Computer- 
world.com.  You  can  reach 
her  at  sharon_machlis@ 
computerworld.com. 


The  virtualization  solution  that  brings  Windows®  Server  2008  and  SUSE®  Linux  Enterprise  Server  together  is  here. 
And  so  is  joint  customer  support  from  Microsoft®  and  Novell®.  So  you  can  run  two,  three  or  even  four  applications 
all  on  the  same  server  with  your  choice  of  operating  system  —  and  get  more  reliability,  flexibility,  efficiency  and 
utilization  than  ever  before.  All  with  clearly  defined  intellectual  property  rights  and  no  support  headaches. 

RUN  WITH  IT  AT  MOREINTEROP.COM  N  OV 6 1 1.  MS&V SC«ll 


Copyright  ©  2008  Novell,  Inc.  and  Microsoft  Corporation.  All  Rights  Reserved.  Novell,  the  Novell  logo  and  SUSE  are  registered  trademarks  of  Novell,  Inc.  in  the  United  States  and 
other  countries  'Linux  is  a  registered  trademark  of  Linus  Torvalds.  Microsoft  and  Windows  Server  are  trademarks  of  the  Microsoft  group  of  companies. 


ELIZABETH  LADA 


HIEF  Technology 
Officer  Arvind 
Thapar  wants  to 
bring  new  green 
technology  to  his 
company,  but  his 
proposed  initia¬ 
tive  —  installing  wind  turbines  to 
generate  power  —  is  decidedly  out¬ 
side  the  usual  realm  of  IT. 

Thapar  is  still  preparing  his  formal 
pitch  to  First  National  of  Nebraska, 
the  Omaha-based  financial  services 
firm  where  he  works,  but  he  says 
initial  reaction  to  the  idea  has  been 
positive  —  something  he  wouldn’t 
have  expected  five  years  ago. 

His  experience  clearly  shows  the 
shifting  winds  of  our  times. 

Leading  businesses  are  looking  for 
ways  to  get  green.  Some  are  motivat¬ 
ed  by  concern  for  the  planet;  others 
by  the  cost  savings  or  the  marketing 
advantages  that  can  come  from  more 
environmentally  friendly  policies. 
Often,  they’re  driven  by  a  combina¬ 
tion  of  factors.  In  any  event,  IT  has  a 
key  role  to  play. 

Here’s  a  checklist  of  suggestions 
from  Computers orldt s  Top  Green 
IT  2008  winners,  to  get  you  started 
and  keep  you  moving  in  a  greener 
direction. 


Buy  renewable  energy. 

This  is  an  easy  one:  Contact 
your  power  company  to  see 
if  it  offers  electricity  from  re¬ 
newable  energy  sources  (many  do), 
such  as  wind  or  solar  power,  says 
Austin  Energy  CIO  Andres  Carvallo. 

There  are  a  few  caveats,  though. 
Unless  you  can  persuade  the  facilities 
folks  to  get  green  energy  for  the  en¬ 
tire  company,  you  might  have  to  limit 
it  to  just  the  data  center  (where  CIOs 
usually  have  more  control  over  power 
supplies).  You’ll  also  have  to  persuade 
the  finance  people  to  shell  out  a  little 
extra  money,  at  least  to  start. 

Carvallo  says  green  energy  usually 
carries  a  premium  —  Austin  Energy 
charges  20%  extra  for  it  —  although 
many  power  companies,  including 
his  own,  lock  in  the  price  for  multiple 
years,  which  means  your  green  pow¬ 
er  could  soon  be  cheaper  than  elec¬ 
tricity  from  conventional  sources. 


3  Use  power  management  tools. 

The  nonprofit  Climate  Sav¬ 
ers  Computing  Initiative 
estimates  that  using  power 
management  features  for  desktop 
computers  can  save  more  than  600 
kilowatt-hours  of  electricity  and 
about  $60  annually  in  energy  costs 
per  computer.  Multiply  that  by  the 
hundreds  —  or  thousands  —  of  PCs 
you  have  in  your  IT  shop,  and  you 
can  see  how  this  simple  action  can 
turn  into  a  lot  of  green. 

To  maximize  energy  savings,  the 
Climate  Savers  Computing  Initiative 
recommends  putting  monitors  and 
hard  drives  to  sleep  after  15  min¬ 
utes  or  less  of  idleness,  with  system 
standby  occurring  after  30  minutes. 


been  printed  so  they  can  spot  excess 
usage  and  try  to  curb  it,  says  CEO 
Larry  O’Connor. 


LOW-HANGING  FRUIT 
FOR  TODAY  AND 
STRETCH  GOALS 
FOR  TOMORROW, 
TO  SAVE  YOU  GREEN 
BY  GOING  GREEN. 


Next  Steps 

1  Virtualize. 

Virtualization  can  yield  signifi¬ 
cant  savings,  says  Larry  Vertal, 
a  member  of  the  board  of  direc¬ 
tors  at  The  Green  Grid,  a  global  con¬ 
sortium  dedicated  to  developing  and 
promoting  energy  efficiency  for  data 
centers  and  information  service  de- 
Continued  on  page  22 


Low-Hanging  Green  Fruit 

1  Limit  paper  use. 

The  paperless  office  is  still  a 
dream.  Each  year,  the  U.S.  goes 
through  4  million  tons  of  copy 
paper,  2  billion  books,  350  million 
magazines  and  25  billion  newspa¬ 
pers.  This  can  lead  to  deforestation, 
and  the  paper  manufacturing  proc¬ 
ess  produces  carbon  dioxide. 

But  IT  can  take  simple  steps  to  cut 
corporate  paper  use. 

London-based  BT  Group  PLC 
moved  printers  from  desktops  to 
central  locations.  That  forces  work¬ 
ers  to  get  up  when  they  want  to 
retrieve  printed  material  —  which 
helps  deter  excess  printing,  says 
Donna  Young,  BT  Group’s  head  of 
environmental  climate  change.  The 
IT  staff  also  set  printers  to  automati¬ 
cally  use  both  sides  of  the  paper. 

Other  World  Computing  in  Wood- 
stock,  Ill.,  controls  paper  use  by 
sending  managers  reports  of  what’s 


SWTOtent  list  of  IBM  trademark  is  available  on  the 


inefficiency,  complexity  and  ever-increasing  power  and  cooling  costs.  Businesses  need  a 


design,  business-driven  IT  model  you’ll  need  for  tomorrow.  This  isn’t  some  far-off  theory. 


world  starts  with  greener  business.  Greener  business  starts  with  IBM 


SYSTEMS.  SOFTWARE.  SERVICES.  FOR  A  GREENER  WORLD 

See  our  Webcast  about  greener  datacenters  at  ibm.com/green/datacenter 


;s  ol, international  Business  Machines  Corporation,  registered  in  many  jurisdictions  worldwii 


Continued  from  page  19 

livery.  He  says  at  least  one  Green  Grid 

member  saw  energy  savings  of  70%. 

Norm  Fjeldheim,  senior  vice  presi¬ 
dent  and  CIO  at  Qualcomm  Inc.  in  San 
Diego,  embarked  on  virtualization  of 
his  data  center  in  2003,  giving  his  team 
just  $250,000  to  fund  the  project. 

At  the  time,  the  company  had  about 
450  servers.  Five  years  later,  with  vir¬ 
tualization  in  the  data  center  about 
70%  complete,  the  company  has  420 
servers  running  more  applications  and 
serving  more  workers. 

Fjeldheim  estimates  that  virtualiza¬ 
tion  has  saved  about  $15  million  in 
avoided  capital  costs  and  about  $4  mil¬ 
lion  to  $5  million  in  power  costs  be¬ 
cause  of  decreased  energy  demands. 

Although  virtualization  has  clear 
green  benefits,  it’s  challenging  to 
implement.  “There  is  a  skill  set  barrier 
and  a  cultural  barrier  to  entry,”  says 
Daniel  Blanchard,  vice  president  of  en¬ 
terprise  operations  at  Marriott  Inter¬ 
national  Inc.  “Many  [business]  people 
want  their  own  system,  and  they  don’t 
want  to  share  with  anybody  else.” 
Marriott’s  IT  shop  has  implemented 
virtualization  projects  in  part  because 
of  the  green  benefits,  he  says. 

2  Facilitate  telecommuting. 

Technology  can  eliminate  a  lot  of 
daily  commuting  and  travel  re¬ 
quirements.  But  IT  must  provide 
the  right  tools,  from  at-home  networking 
capabilities  to  audioconferencing  and 
online  collaboration  systems. 

At  BT  Group,  those  tools  allow 
about  10%  of  employees  to  work  full 
time  from  home  and  70%  to  have  flex¬ 
ible  work  arrangements,  Young  says. 
The  company  also  has  invested  in 
technologies  for  virtual  meetings  and 
collaboration,  reducing  the  need  for 
employees  to  travel  between  sites. 

Young  says  these  initiatives  have 
prevented  the  production  of  97,600  tons 
of  carbon  dioxide  that  commuting  and 
traveling  would  have  generated.  (Com¬ 
pany  studies  have  also  shown  that  the 
initiatives  increased  productivity  by 
21%  and  reduced  sick  time  by  63%.) 

3  Include  green  objectives 
in  procurement  policies. 

IT  procurement  policies  have 
long  specified  product  perfor¬ 


mance  standards.  It’s  now  time  to  add 
environmental  standards  to  that  list. 

Fjeldheim  tweaked  his  shop’s  evalua¬ 
tion  criteria  several  years  ago,  expand¬ 
ing  financial  considerations  from  pur¬ 
chase  price  to  total  cost  of  ownership. 
That  means  looking  at  a  device’s  total 
life  cycle,  power  consumption,  recy¬ 
cling  costs  and  other  environmental 
factors.  “That  was  a  little  bit  of  a  mind 
shift  for  us,  but  when  you  start  to  think 
about  it  strategically,  over  the  life  of 
the  product,  it  starts  to  be  an  easier  de¬ 
cision,  and  it’s  easier  to  sell  to  finance,” 
Fjeldheim  explains. 

Taking  such  action  is  easier  now 


No-brainers 


Here  are  some  green  initiatives  even 
lower  than  the  low-hanging  fruit: 

MAKE  RECYCLING  OBVIOUS.  Put 

bins  for  paper,  plastics,  cans,  etc., 
throughout  the  office  so  there’s  no 
excuse  for  not  recycling. 

REWARD  WORKERS  WHO  USE  THE 
SHOE-LEATHER  EXPRESS.  Aus¬ 
tin  Energy  gives  S60  a  month  to 
employees  who  walk,  bike  or  find 
other  nonmotorized  transportation 
to  and  from  the  office. 

RECYCLE  IT  EQUIPMENT.  Give  an 
employee  the  responsibility  and  it 
will  happen. 

THINK  BEFORE  BUYING.  Develop 
rigorous  reviews  and  procurement 
policies  to  make  sure  you  buy  only 
what  you  need. 

-  MARY  K.  PRATT 


than  ever,  Carvallo  adds,  because  ven¬ 
dors  provide  more  details  about  their 
products’  environmental  impact  and 
energy  requirements,  and  the  federal 
Energy  Star  efficiency  rating  system 
now  applies  to  computer  equipment. 

Stretch  Goals 

Get  a  better  grip  on 
data  center  demands. 

It’s  no  secret  that  data  center 
cooling  gobbles  up  energy.  Ac¬ 
cording  the  federal  Data  Center  Energy 
Efficiency  Program,  data  centers  used 
61  billion  kWh  of  electricity  in  2006 


—  double  the  amount  used  in  2000  and 
1.5%  of  all  the  electricity  consumed  in 
the  U.S. 

Virtualization  can  help  rein  in  those 
figures,  but  companies  can  go  further 
by  better  monitoring  and  managing 
cooling  requirements. 

Working  with  computer  room 
air  conditioning  (CRAC)  units, 
Blanchard’s  team  measures  tempera¬ 
tures  across  the  data  center  to  match 
cooling  needs  with  cooling  output. 

This  requires  an  investment  of 
staff  time,  but  there’s  a  good  payoff-: 
Blanchard  says  he  has  been  able  to 
turn  off  four  of  Marriott’s  two-dozen 
CRAC  units  while  turning  up  the 
temperature  on  other  CRAC  units  by 
several  degrees.  This  has  cut  power 
consumption  by  7%,  Blanchard  says. 

Marriott  does  this  monitoring  and 
adjustment  manually,  but  its  long-term 
goal  is  to  automate  the  process. 

Replace  inefficient  equipment. 

Marriott  actively  tracks  the 
life  cycle  of  its  assets,  so  IT 
workers  know  when  it’s  cost¬ 
ing  more  to  run  a  particular  asset  than 
it  would  cost  to  buy  and  run  some¬ 
thing  new.  “Across  the  board,  newer 
equipment  is  more  efficient  than  older 
equipment,  so  the  stretch  goal  is  to 
replace  older  equipment  with  newer 
pieces,”  Blanchard  says. 

Achieving  that  goal  can  require 
some  significant  upfront  investment, 
however,  so  you’ll  need  to  know  just 
how  big  your  energy  savings  will  be 

—  in  dollars,  not  just  kilowatt-hours 

—  if  you  want  to  sell  this  initiative  to 
the  finance  people. 

Make  sure  you’re  combining  new 
purchases  with  other  energy-reducing 
and  environmentally  friendly  initia¬ 
tives,  Blanchard  says.  For  example, 
don’t  just  replace  an  old  server  with  a 
newer  model.  Though  you’ll  see  savings 
from  the  exchange,  you’ll  maximize  the 
return  on  your  new  equipment  if  it’s 
part  of,  say,  a  virtualization  project. 

Manage  assets  more  aggressively. 

In  a  typical  data  center,  no 
one  knows  what  10%  to  14%  of 
the  servers  are  doing,  so  keep¬ 
ing  better  track  of  your  assets  and 
curbing  unnecessary  use  can  yield 
good  savings,  says  Winston  Bumpus, 


jj 

IJ 


s 


THE  DATA  CENTER  ENERGY  PROFILER, 

or  DC  Pro,  from  the  U.S.  Department  of 
Energy,  is  an  online  software  tool  that 
helps  companies  diagnose  how  energy 
is  being  used  in  their  data  centers  and 
how  they  can  save  energy  and  money. 
wwwt.eere.energy.gov/industry/ 
saveenergynow/partnering.data. 
centers.html 

THE  GREEN  GRID  is  a  global  consor¬ 
tium  dedicated  to  advancing  energy 
efficiency  in  data  centers  and  business 
computing  ecosystems. 

www.thegreengrid.org/home 

THE  CLIMATE  SAVERS  COMPUTING 

INITIATIVE  is  a  nonprofit  group  of  con¬ 
sumers,  businesses  and  conservation 


•  A  7,  W  ,7',  ,7:  -V-  '  '-7.  '  '  '  7 

' 

organizations  whose  goal  is  to  promote 
the  development,  deployment  and 
adoption  of  smart  technologies  to  both 
improve  the  efficiency  of  a  computer’s 
power  delivery  and  reduce  energy 
consumption. 

www.ciimatesaverscomputing.org 

■  THE  GREEN  ELECTRONICS  COUNCIL 

promotes  the  effective  design, 
manufacture,  use  and  recovery 
of  electronic  products. 

www.greeneiectronicscouncii.org 

«  THE  ELECTRONIC  PRODUCT  ENVIRON¬ 
MENTAL  ASSESSMENT  TOOL,  or  EPEAT, 
is  an  environmental  procurement 
tool  to  help  institutional  purchasers 
evaluate,  compare  and  select  desktop 
computers,  notebook  computers  and 
monitors  based  on  their  environmental 
attributes. 

www.greeneiectronicscouncii.org/ 

epeat/index.htm 


another  Green  Grid  director. 

That’s  what  BT  Group  did.  It  found 
that  many  of  its  workers  had  unsanc¬ 
tioned  servers  under  their  desks.  “It 
was  for  a  side  project,  and  it  made  it 
a  little  easier  for  them,”  Young  says. 

But  those  rogue  servers  were  eating 
up  energy  needlessly  because  existing, 
sanctioned  servers  could  have  easily 
handled  their  workload. 

The  IT  department  has  cracked 
down  on  unnecessary  or  inefficiently 
used  equipment.  For  example,  a  cell 
phone  charger  that’s  plugged  in  when 
the  phone  isn’t  charging  still  draws 
power,  as  does  an  empty,  unneeded 
server  rack  that’s  still  plugged  in. 

To  reach  its  goals,  the  company  has 
run  three  “energy  challenges,”  during 
which  it  rewards  IT  workers  with  up  to 
$2,000  if  they  identify  equipment  that 
is  running  but  not  needed. 

Long-Term  Targets 

1  Build  green. 

When  Monsanto  Co.  built  its  new 
data  center  at  its  campus  in  Creve 
Coeur,  Mo.,  it  wanted  to  be  more 
than  a  technology  leader;  it  wanted  to 
be  an  environmental  leader,  too.  So  it 
earned  Leadership  in  Energy  Efficient 
Design  (LEED)  certification  for  the 
40,000-square-foot  facility. 

This  provides  more  than  bragging 
rights.  The  new  data  center  requires 
about  30%  less  energy  than  a  conven¬ 
tionally  designed  one,  says  CIO  Mark 
Showers.  The  design  incorporated 
energy-efficient  elements  such  as  natu¬ 
ral  light  and  multiple  cooling  options 
(including  the  use  of  naturally  chilled 
outdoor  air  when  possible).  In  addition, 
10%  of  the  data  center’s  power  supply 
comes  from  renewable  power  sources. 

Showers  says  it  took  time  and  plan¬ 
ning  to  get  to  this  point.  For  instance, 
the  company  had  to  consolidate  applica¬ 
tions  over  the  past  decade  so  all  world¬ 
wide  transactions  would  flow  through 
the  Creve  Coeur  site.  And  the  decision 
to  pay  the  extra  costs  —  just  under  5% 
of  the  $21  million  total  —  for  the  LEED- 
level  data  center  wasn’t  taken  lightly. 

“But  there  was  a  sense  that  this  was 
the  right  thing  to  do.  We’re  an  agri¬ 
cultural  company,  and  our  business 
is  about  sustainable  yields  and  food 
product,  so  it  fit  very  cleanly  and  nice¬ 
ly  into  our  culture,”  Showers  says. 


2  Calculate  and  manage 
your  energy  needs. 

How  efficient  is  your  data  cen¬ 
ter?  If  you  don’t  know,  you’re 
not  alone.  But  Bumpus  says  companies 
should  strive  to  find  out.  “It’s  an  impor¬ 
tant  measurement,”  he  says. 

To  begin  to  calculate  efficiency,  com¬ 
panies  need  to  know  how  much  power 
is  required  per  transaction,  Bumpus 
explains. 

Companies  also  need  to  determine 
how  much  energy  is  used  while  serv¬ 
ers  are  idle,  he  says,  noting  that  most 
idle  servers  tend  to  consume  60%  of 
the  power  required  for  peak  work¬ 
load.  Such  figures  give  you  a  baseline 
against  which  to  set  goals  and  judge 
progress. 

As  organizations  get  a  better  handle 
on  data  center  efficiency  and  de¬ 
velop  best  practices  and  standards  for 
achieving  it,  they  can  move  to  the  next 
step,  according  to  The  Green  Grid’s 
Vertal  and  Bumpus. 

That  entails  using  tools  that  dynami¬ 
cally  manage  the  data  center,  mov¬ 
ing  workloads  around  (maybe  even 
to  other  geographic  sites),  powering 
down  machines  that  aren’t  needed  and 
automatically  bringing  up  machines 


when  they’re  required. 

“As  we  move  to  the  next  five  years, 
data  centers  have  to  be  more  flexible 
and  agile,”  Vertal  says. 

Adopt  new  technologies. 

Green-thinking  companies 
should  press  vendors  to  de¬ 
liver  innovations  such  as  water- 
cooled  server  racks  for  data  centers 
and  improvements  in  virtualization 
technology.  And  they  should  try  green¬ 
er  options  when  available. 

Marriott  did.  Its  new  Recovery  and 
Development  Center  will  be  sited  in 
Iron  Mountain  Inc.’s  145-acre  under¬ 
ground  facility  in  a  naturally  cooled 
limestone  cave  in  western  Pennsyl¬ 
vania.  “We’re  trying  to  do  as  much  as 
we  can  with  the  natural  resources,” 
Blanchard  says. 

Blanchard  acknowledges  that  ma¬ 
jor  steps  like  that  require  fairly  large 
investments  of  time  and  money,  as 
well  as  a  pioneering  spirit.  But  he  says 
companies  need  to  embrace  the  next 
generation  of  technology  if  they  want 
to  build  greener  operations.  @ 

Pratt  is  a  Computerworld  contributing 
writer  in  Waltham,  Mass.  Contact  her  at 
marykpratt@verizon.net. 


Companies  spend  millions  of  dollars  on  energy  to  store  their  information.  A  problem  that 
is  only  getting  worse-for  IT  budgets  and  for  the  planet.  IBM  has  a  broad  range  of  information 
management  solutions  to  help  companies  use  their  information  more  strategically  and 
efficiently.  From  deep  data  compression  capabilities  that  reduce  storage  requirements  by 
up  to  80%  to  smart  archiving  that  improves  application  performance.  Information  on  Demand 
helps  companies  extract  real  business  value  from  their  information  without  wasting  money 
and  energy.  A  greener  world  starts  with  greener  business.  Greener  business  starts  with  IBM. 


Learn  how  to  do  more  with  less.  Get  the  eBook  at  ibm.com/green/data 


ijjhv  l&MfjlfKHBM  log$an<hbnt{|onr>  trademarks International  Business  Machines  Corporation.  registered  in  many  jurisdictions  worldwide  A  current  list  of  IBM  trademarks  is  available  oh  the 
$t  •.'Cbpyngbr f^.trad^ntew^oiTOation''  at  vi'Wi(if:ilitrn.com/legal/copytrade.'shtrni.  ©‘2008  IBM  Corporation.  All  rights-  reserved 


Cloud-enabling 
Your  Software 

Licenses 


Here’s  how  to 
move  forward 
while  keeping 
your  feet  on 
the  ground. 

By  Joaquin 
Gamboa  and 
Marc  Lindsey 

■  . «^HE  PROMISE  of  moving 

your  company’s  software 
and  data  systems  into  the 
cloud  grows  more  enticing 
- Jm by  the  day.  Virtualization, 
cloud  computing  and  grid  networks 
have  a  lot  to  offer  enterprise  users.  But 
you  could  put  your  company  and  your 
job  at  risk  if  you  fail  to  consider  certain 
factors  that  are  key  to  getting  the  right 
license  at  the  right  price. 

Whether  you  plan  to  use  your  own 
grid  infrastructure  or  someone  else’s 
cloud  computing  platform,  your  licens¬ 
ing  structures  must  accommodate 
the  applicable  virtual  environment. 
Although  many  factors  should  be  con¬ 
sidered  when  licensing  software,  we’ll 
focus  on  the  available  framework  for 
licensing  proprietary  software,  with  vir¬ 
tualization  and  grid  computing  in  mind. 

Unlike  in  a  typical  computing  envi¬ 
ronment,  virtualization,  coupled  with 
grid  computing,  enables  the  disaggrega¬ 
tion  of  operating  systems,  middleware, 
data  stores  and  application  software 
from  the  limitations  of  physical  ma¬ 
chines  and  the  local-area  network.  This 
new  world  is  colliding  with  traditional 
vendor  licensing  practices,  producing 
software  compliance  nightmares  for 
both  licensees  and  licensors,  and  often 
resulting  in  irrational  license  fees. 

LEGACY  LICENSING  PRACTICE 

Traditional  licenses  fall  into  one  of 
these  three  categories: 

»The  CPU  license  is  typical  for  oper¬ 
ating  system  software,  middleware  and 
some  application  software.  It  enables 
licensees  to  use  the  software  on  one 

Continued  on  page  28 


23  COMPUTERWORLD  SEPTEMBER  8,  2008 


iMjS&P) 


mMM. 

. 


V-  •' 


the  more  reliability  matters. 


Fujitsu  ETERNUS®  Storage  Systems:  Uncompromising 
reliability  for  your  most  demanding  applications. 


To  help  enterprises  manage  the  flood  of  mission-critical  data,  Fujitsu  ETERNUS  Storage  Systems  deliver  the 
reliability  and  availability  data  centers  require.  For  continuous  data  access  and  easier  maintenance,  major 
components  are  redundant  and  hot-swappable.  The  controller  modules’  software  can  also  be  upgraded 
without  shutting  down  or  rebooting.  A  built-in  statistical  failover  mechanism  ensures  stable  operation  by  disabling 
components  exhibiting  intermittent  failures.  Furthermore,  disk  data  encryption  using  1 28-bit  AES  provides  security 
against  data  theft.  The  ETERNUS  Storage  Systems  range  from  the  new,  low-cost  ETERNUS  2000,  designed  for 
small  and  medium  businesses;  to  the  ETERNUS  8000  designed  for  large  enterprise  applications  and  is  available 
with  up  to  2  PB  of  storage.  Go  to  us.fujitsu.com/computers/reliablestorage  for  more  information. 


DATA  PROTECTION — Online,  efficient  disk-to-disk 
backup  using  tiered  storage 


DISASTER  RECOVERY— Cost-effective  WAN 
optimization,  secure  remote  data  replication  over 
iSCSI  with  IPsec  data  encryption 


FUJITSU 


THE  POSSIBILITIES  ARE  INFINITE 

©  2003  Fujitsu  Computer  Systems  Corporation.  All  rights  reserved.  Fujitsu,  the  Fujitsu  logo  and  ETERNUS  are  registered  trademarks  of  Fujitsu  Limited.  All  other  trademarks  mentioned  heroin  are  the  property  ot  their  respective  ov.r 


■  IT  MENTOR 


ENTERPRISES  OFTEN  license  critical 
software  on  a  perpetual  basis  by  pay* 
ing  a  one-time  upfront  fee  in  exchange 
for  the  right  to  use  the  licensed  soft¬ 
ware  indefinitely  under  the  terms  and 
conditions  of  a  license  agreement.  In 
recent  years,  an  alternative  licens¬ 
ing  approach  known  as  software  as 
a  service  has  offered  enterprises  an 
attractive  alternative  for  certain  types 
of  software. 

SaaS  is  attractive  because  it  entirely 
shifts  the  burden  of  running  and  main¬ 
taining  an  infrastructure  to  support 


a  particular  application.  With  SaaS, 
users  only  need  the  infrastructure  to 
access  and  connect  to  the  provider’s 
data  center. 

Despite  its  simplicity  and  attractive 
pay-as-you-go  monthly  pricing,  there 
is  little  evidence  that  SaaS  will  com¬ 
pletely  replace  perpetually  licensed 
software  in  the  enterprise.  Conse¬ 
quently,  enterprises  will,  at  least  for 
some  software,  continue  to  work  with¬ 
in  the  confines  of  a  perpetual  license 
construct  for  the  foreseeable  future. 

-  JOAQUIN  GAMBOA  AND  MARC  LINDSEY 


Continued  from  page  26 
machine  and  often  identifies  specific 
compatible-equipment  configurations. 
Any  equipment  configuration  limita¬ 
tion  is  generally  based  on  design,  not 
license  compliance.  For  some  software 
(for  example,  certain  middleware  serv¬ 
er  software),  the  licensed  product  may 
support  alternative  or  enhanced  server 
configurations,  but  separate  license  en¬ 
titlements  must  be  purchased. 

Under  a  CPU  license,  the  fee  may 
vary  based  on  the  processing  power 
of  the  designated  CPU.  The  number  of 
users  who  access  the  licensed  software 
is  irrelevant. 

The  biggest  problem  with  CPU 
licenses  in  a  grid  or  cloud  context  is 
that  licensors  expect  licensees  to  buy 
additional  licenses  for  each  processor 
(by  number  and  type)  that  executes  the 
licensed  software.  This  is  true  even  if 
multiple  virtual  machines  or  proces¬ 
sors  are  simply  sharing  the  load  — 
without  increasing  capacity  or  trans¬ 
action  volume  —  of  a  much  smaller 
number  of  legacy  physical  machines  or 
CPUs.  In  a  cloud  environment  running 
multiple  virtual  machines,  license  fees 
can  easily  rise  because  various  proces¬ 
sors  are  running  the  licensed  software. 

»The  seat  license  designates  the 
number  of  “seats”  that  can  use  the  soft¬ 
ware.  The  license  entitlement  doesn’t 
flow  to  any  specific  users.  There  are 
two  common  seat  license  methods. 

The  first  calculates  the  fee  by  count¬ 
ing  the  total  number  of  people  who  use 
the  software.  This  method  correlates 


poorly  with  actual  use.  There  may  be 
a  significant  number  of  potential  users 
who  rarely  or  never  actually  use  the 
software.  Worse,  some  licenses  define 
a  chargeable  seat  as  an  instance  of  a 
user  accessing  the  software  from  a  par¬ 
ticular  machine  (virtual  or  otherwise). 
Consequently,  a  single  user  or  device 
can  give  rise  to  multiple  seats  —  caus¬ 
ing  the  licensee  to  pay  multiple  times 
for  use  by  one  individual  or  device. 

The  second  method  determines  the 
license  fee  by  calculating  the  total 
number  of  concurrent  users  permit¬ 
ted  to  access  the  software  at  one  time. 
This  more  closely  corresponds  to  li¬ 
censee  use  patterns  than  the  total-seat 
license  because  occasional  users  can 
be  discounted  when  determining  how 
many  seats  to  purchase. 

Of  these  two,  the  concurrent-user 
seat  license  may  be  the  most  desirable 
if  you’re  moving  to  grid  computing 
and  a  virtualized  infrastructure.  Un¬ 
der  concurrent-user  models,  licensees 
should  be  charged  based  upon  the 
greatest  number  of  seats  (whether 
individuals  or  devices)  that  use  the  ap¬ 
plication  at  any  one  time.  Whether  the 
users  operate  one  or  more  physical  or 
virtual  machines  shouldn’t  matter. 

This  can  be  an  imperfect  indicator  of 
usage  patterns,  however,  because  not 
all  users  are  equal.  A  company  that  has 
many  power  users  would  pay  the  same 
fee  as  a  company  with  an  equal  number 
of  users  whose  usage  is  average.  And 
from  the  licensor’s  perspective,  the 
concurrent-user  model  is  undesirable 


for  back-office  or  middleware  software, 
since  a  few  administrative  users  can 
serve  as  transaction  conduits. 

»The  enterprise  or  site  license  allows 
the  licensee  to  use  the  software  with¬ 
out  geographic  limitations,  specific 
limits  on  the  number  of  users  or  de¬ 
vices  accessing  the  software,  arbitrary 
processor  accounting  rules,  or  prohibi¬ 
tions  on  the  number  of  copies  made 
or  used  by  the  licensee.  There  may  be 
restrictions  on  the  types  or  configura¬ 
tion  of  the  equipment  on  which  the 
software  may  be  installed,  as  well  as 
some  business  operation  boundaries. 

The  site  license  is  a  variant  that 
restricts  to  a  specific  site  either  the 
installation  or  the  location  from  which 
users  can  access  the  software.  Each  ad¬ 
ditional  site  requires  a  new  license. 

Large  companies  regularly  negotiate 
long-term  custom  enterprise  and  site 
licenses.  These  require  lengthy  nego¬ 
tiations  and  large  lump-sum  payments 
to  the  licensor.  Given  the  cost  and  ne¬ 
gotiation  leverage  necessary  to  make 
this  strategy  work,  enterprise  and  site 
licenses  are  often  impractical. 

THE  PATH  FORWARD: 

THE  TRANSACTIONS  LICENSE 

There’s  another,  better  licensing  struc¬ 
ture  that  fairly  balances  the  interests 
of  licensors  and  licensees:  a  transac¬ 
tions  license.  This  embraces  some  of 
the  elements  of  an  enterprise  license, 
but  it  is  adapted  to  serve  organizations 
of  all  sizes. 

Applying  a  transactions  license,  the 
licensee  can  use  the  software  without 
geographic  limitations,  restrictions  on 
the  number  of  users  or  devices  access¬ 
ing  the  software,  or  arbitrary  processor 
accounting  rules.  There  are  no  limits  on 
the  number  of  copies  or  instances. 

The  license  fee  and  entitlements  are 
based  on  the  licensee’s  transaction  vol¬ 
ume.  As  long  as  the  actual  transaction 
volume  is  within  a  preset  range,  there  is 
no  need  to  purchase  additional  license 
entitlements  or  receive  underutilization 
credits.  The  transaction  limits  can  be 
tailored  as  narrowly  or  as  broadly  as 
the  licensees  and  licensors  agree. 

To  keep  track  of  transaction  vol¬ 
umes,  the  licensed  software  can  be 
enabled  with  software  agents  that 
monitor  and  report  on  the  transaction 
Continued  on  page  30 


28  COMPUTERWORLD  SEPTEMBER  8,  2008 


STFni$tOUSE 


Brands  that  have  revolutionized  online 


business  have  one  thing  in  common... 


URGER  KING®  serves  over  1 1  million  guests  a  day, 
i/orldwide  —  in  1 1 ,455  restaurants  in  70  countries.  The 
lerformance  and  availability  of  its  online  SAP®  portal  is 
ritical  to  corporate,  partner  and  franchisee  operations, 
rom  ordering  buns  to  conducting  real-time  labor 
cheduling  to  interoffice  communications,  Akamai's 
ervices  have  enabled  the  'HOME  OF  THE  WHOPPER®' 
o  revolutionize  its  global  Web  applications. 


Akamai 


A  lot  can  happen  in  ten  years.  Especially  with  Internet 
technology  that's  revolutionizing  virtually  every  facet 
of  business.  New  sales  channels.  New  applications  and 
business  processes.  In  our  first  ten  years,  Akamai  has 
helped  the  world's  leading  businesses  become  the 

world's  lead  ing  online  businesses.  And  we're  just 

.  .  ■  ■■  c  ,  •  . 

geumg  siariea. 

:  v  :  ■  •  . 

I  oairri  rvi/Mr^:  :iA/iA/iAr  -a  Xr  ca  nri/sa  i  .taW  R 

v 

;  :  - ' c.. *;;•  v 

•  ,  •,  •••' <••••>' 

7 ,4  ’  ■  V  v  ‘-  «  '  '  V'C  ■/■*+■  '  0 

■  .■  ■  v* ,.v.  •  v  UM&s 

■  ■  ■  ■  -v.  feiflfi 

■  T  ■  ■  •■■■''  '■  .• 


...Akamai,  Enabling  the  Revolution 


WELCOME 


Bunaen 


KING'S 


rents' 


HeY  P° 


Internet  revolutionary 


■  IT  MENTOR 


Standards,  Security 
And  Data  Handling  in 
A  Cloud  Environment 


Here  are  some  oilier 
important  issues  to 
consider  when  selecting 
a  cloud  vendor  or 
services  provider: 


STANDARDS 

Whether  you’re  running  your 
own  cloud  or  depending  on 
someone  else’s,  you’ll  want 
to  ensure  that  your  early 
investments  in  virtualization 
are  good  for  the  long  haul.  To 
the  extent  possible,  get  as¬ 
surances  from  your  vendors 
and  cloud  providers  that 
the  systems  you’re  buying 
are  standards-based,  will 
operate  with  other  systems 
you  intend  to  adopt  as  part 
of  your  technology  strategy, 
and  are  able  to  grow  with 
your  business  -  both  in  terms 
of  capacity  and  complexity. 

If  you’re  using  someone 
else’s  cloud,  make  sure  that 
you’re  not  creating  an  exten¬ 
sive  set  of  APIs  or  function 
calls  that  are  proprietary 
to  that  cloud  provider.  The 
greater  your  investment  in 
your  virtualized  environ¬ 


ment,  the  more  you  will  be 
locked  into  that  specific 
cloud  provider. 


SECURITY 

Security  vulnerabilities  may 
occur  in  a  virtualized  envi¬ 
ronment  for  various  reasons 
(e.g.,  design  defects,  poor 
patch/update  management, 
ineffectual  authentica¬ 
tion  controls,  storage  and 
transmission  of  sensitive 
data  without  encryption,  and 
inadequate  procedures  for 
security  incident  monitoring, 
reporting  and  mitigation).  To 
increase  the  likelihood  that 
your  virtualized  environment 
will  be  sufficiently  secure, 
make  security  one  of  the 
determining  factors  in  the 
evaluation  and  selection  of 
both  software  and  services 
vendors. 

In  your  evaluation  of  soft¬ 
ware  vendors,  consider  the 
following  factors: 

■  The  relative  importance 
that  the  vendor  has  placed 
on  security  in  its  design  of 
the  software. 


■  The  processes  the  vendor 
has  in  place,  and  the  com¬ 
mitment  it’s  willing  to  make, 
to  update  the  software’s 
security  throughout  the  term 
of  the  license. 

■  The  compatibility  of  the 
software’s  security  design 
and  mechanisms  with  the 
other  components  of  your 
virtual  environment. 

In  your  evaluation  of  a 
cloud  manager  or  provider, 
consider  the  vendor’s  physi¬ 
cal  and  logical  security  prac¬ 
tices,  processes  and  man¬ 
agement  approaches,  and  its 
willingness  to  comply  with 
your  security  policies  and 
procedures.  Your  negoti¬ 
ated  agreement  with  a  cloud 
manager  or  provider  should 
do  the  following: 

■  Enable  you  to  conduct  pe¬ 
riodic  security  assessments. 

■  Assign  responsibility  for 
security  incident  detection, 
reporting,  response  and 
mitigation. 

■  Include  a  process  for  man¬ 
agement  escalation  of  unre¬ 
solved  security  problems. 


DATA  HANDLING 

Protecting  sensitive  cor¬ 
porate  and  customer  data 
should  be  a  priority  if  you’re 
considering  a  virtualized 
environment  that  enables  a 
vendor  to  manage  or  store 


that  data.  Before  you  put 
your  data  in  the  hands  of 
a  vendor,  demand  that  the 
vendor  demonstrate  its  data 
protection  and  business 
continuity  capabilities.  And 
when  you  decide  to  move 
forward,  make  sure  that 
your  negotiated  agreement 
is  explicit  about  the  vendor’s 
ongoing  obligations  to  pro¬ 
tect  your  data  and  holds  the 
vendor  liable  for  failure  to 
satisfy  those  obligations. 

If  your  company  operates 
internationally  or  in  certain 
industries  in  the  U.S.  (e.g., 
financial  services  or  health 
care),  your  negotiated 
agreement  should  require 
the  vendor  to  comply  with 
applicable  data-protection 
and  privacy  laws. 

The  negotiated  agreement 
should  also  do  the  following: 

■  Incorporate  the  relevant 
portions  of  your  privacy  poli¬ 
cies  and  obligate  the  vendor 
to  conform  to  them. 

■  State  that  your  company 
owns  its  data,  has  access  to 
that  data  at  its  discretion, 
and  will  receive  the  data 
upon  the  expiration  or  termi¬ 
nation  of  the  agreement. 

«  Describe  the  parties’  re¬ 
sponsibilities  when  it  comes 
to  recovering  lost  data. 

-  JOAQUIN  GAMBOA  AND 
MARC  LINDSEY 


Continued  from  page  28 
volume  during  the  appropriate  mea¬ 
surement  period.  (Annually  makes  the 
most  sense.  It  accounts  for  seasonality 
and  avoids  introducing  too  many  bur¬ 
densome  electronic  audits.) 

Determining  which  transactions  for 
a  given  piece  of  software  will  be  relied 
on  for  pricing  and  then  developing 
reliable  monitoring  agents  are  among 
the  technical  challenges  transactions 
licenses  present.  Forward-thinking 
licensors  should  be  motivated  to  over¬ 
come  these  challenges,  however,  be¬ 
cause  the  rewards  are  worth  the  effort. 


Licensors  will  be  able  to  offer  many 
of  their  potential  customers  a  more  ra¬ 
tional  pricing  option  that  doesn’t  force 
them  to  purchase  more  license  entitle¬ 
ment  rights  than  they  actually  use 
initially  and  allows  them  to  purchase 
more  as  needed.  Because  licensees 
won’t  feel  cheated  by  the  licensor,  more 
will  resist  the  temptation  to  abuse  their 
license  rights.  Licensors  that  evolve 
their  software  designs  and  license 
practice  to  keep  pace  with  the  virtual¬ 
ization  and  grid  computing  technolo¬ 
gies  will  have  a  competitive  advantage. 

The  promises  of  virtualization  and 


cloud  computing  are  tempting.  But 
when  moving  forward  with  virtualiza¬ 
tion,  make  sure  your  head  is  not  lost  in 
the  clouds.  You  should  be  clear  about 
what  you’re  getting  yourself  into.  Iden¬ 
tify  the  real  costs,  pin  down  the  scope 
of  your  use  rights,  put  protections  in 
place  in  case  things  don’t  go  as  planned, 
and  lay  a  strong  licensing  foundation 
that  will  serve  you  in  the  future.  ■ 
Gamboa  and  Lindsey  are  partners  at 
Washington  law  firm  Levine,  Blaszak, 
Block  &  Boothby  LLP  (www.lb3law. 
com).  Contact  them  at  jgamboa@ 
lb3law.com  and  mlindsey@lb3law.com. 


i 0  COMPUTERWORLD  SEPTEMBER  8,  2008 


' 


fr«!40llTBl« 


rEH24G4  T8IB 


.V?  ->~n-  > 


Evolve  your  telephony  with  software  and  leave  the  PBX  in  place. 


Transition  to  VoIP  with  innovative  software  from  Microsoft. 
Software  that  integrates  with  Windows  Server  Active  Directory 
services,  Microsoft  Office,  and  Microsoft  Exchange  Server. 
Keep  your  existing  PBX  hardware  and  still  get  new  voice 
capabilities  like  drag-and-drop  conferencing,  anywhere 
access,  and  click-to-call  functionality  from  familiar  desktop 


applications.  A  software-powered  VoIP  solution,  based 
on  Microsoft  Office  Communications  Server  2007,  helps 
you  increase  the  productivity  and  flexibility  of  your 
workforce— especially  your  mobile  users.  Change  the 
way  you  communicate  without  switching  your  switch. 
Learn  more  atmicrosoft.com/voip  -'"yiP/ ’ 

•  -  ‘  '■  •  ..  *  -  .  '  '  ' 

Your  potential.  Qur  passion. 

Microsoft 


m  SOFTWARE 


Creating  a  single  billing 
system  from  13  saves  Verizon 
Wireless  $20  million 
annually.  By  Julia  King 


1A  A  BEST  IN 
CLASS 

IvTvy  This  story 

IT  LEADERS  2008  is  part  of  an 
ongoing  series  showcasing  the 
best  projects  of  this  year’s 
Premier  100  IT  Leaders. 


Verizon 

Wireless 

IT  CHAMPION: 

Ajay  Waghray,  CIO 
IT  STAFFERS:  2,394 
PROJECT  PAYBACK: 
$20  million  annually 


ii 


ESS  IS  MORE”  is 
the  IT  philosophy 
in  operation  at 
Verizon  Wireless. 
In  fact,  the  telecommuni¬ 
cations  company’s  2008 
Premier  100  Best  in  Class 
project  was  a  study  in  the 
benefits  of  slimming  down. 
By  consolidating  13  billing 
systems  into  a  single  enter¬ 
prise  system,  the  company 
is  now  saving  $20  million 
annually. 

But  according  to  Ajay 
Waghray,  a  2008  Computer- 
world  Premier  100  IT  Leader 
honoree  and  CIO  at  the 
$44  billion  Basking  Ridge, 
N.J.,  company,  neither  data 
nor  systems  integration 
proved  to  be  the  biggest 
challenge  in  the  project.  In¬ 
stead,  it  was  innovating  and 


optimizing  the  hundreds  of 
business  processes  that  the 
various  systems  automated. 

“Billing  systems  are  the 
keepers  of  all  the  customer 
data  and  rules  of  engage¬ 
ment.  To  simplify  the  cus¬ 
tomer  experience,  you’ve 
got  to  simplify  what  you’re 
servicing,”  Waghray  says. 

The  first  step  was  as¬ 
sembling  a  cross-functional 
team  whose  members  rep¬ 
resented  every  step  in  a 
customer’s  experience, 
from  marketing  and  sales  to 
network  operations,  store 
operations  and  support. 

The  deadline  was  tight: 

18  months  to  standardize 
and  implement  a  single  set 
of  business  processes  that 
would  ultimately  make  it 
possible  to  ensure  that  every 
customer  who  walked  into 
one  of  the  company’s  2,400 
stores  would  walk  out  with 
an  activated,  ready-to-use 
wireless  phone. 

Next  came  the  long,  hard 
work  of  deciding  which  proc¬ 
esses  should  be  retained  to 
best  serve  the  company’s 
69  million  subscribers. 

“We  had  multiple  varia¬ 
tions  of  multiple  practices 
and  policies.  We  had  differ¬ 
ent  systems,  which  spawned 
different  approaches  to  busi¬ 
ness  problems,”  recalls  John 
Bianchi,  director  of  custom¬ 


er  service  and  a  member  of 
the  original  cross-functional 
team.  “What  we  did  is  roll 
up  our  sleeves  and  plow 
through  all  of  these  custom¬ 
er  interactions.  We  looked 
for  the  simplest  and  most 
efficient  processes  and  then 
asked  IT  to  automate  those 
processes.” 

“The  whole  thinking  was 
that  less  is  more,”  Waghray 
emphasizes.  “That  means 
fewer  applications  to  man¬ 
age,  fewer  rules  of  engage¬ 
ment,  fewer  touch  points  for 
customers.” 

PULLING  IN  THE  DATA 

Once  the  processes  were 
decided,  data  elements 
from  the  old  billing  systems 
needed  to  be  imported  into 
the  new  system.  This  meant 
that  each  and  every  data  ele¬ 
ment  in  a  customer’s  file  had 
to  be  mapped  into  the  new 
enterprise  system  in  a  stan¬ 
dardized  way.  To  do  that, 
Waghray  says,  the  IT  team 
adopted  a  standard  format 
for  importing  data  from  the 
13  different  systems  into  the 
new  in-house  billing  system, 
which  runs  on  a  combina¬ 
tion  of  distributed  and 
mainframe  platforms. 

Today,  this  single  billing 
system  is  the  primary  reposi¬ 
tory  for  all  customer,  pricing 
and  service  package  data  —  a 
setup  that  works  to  create 
consistency  across  all  of  the 
company’s  service  areas. 

“For  example,  we  have 
both  business  and  consumer 
customers  that  have  a  need 
for  accounts  in  multiple  ge¬ 


ographies.  Before,  they  had 
separate  accounts,”  Bianchi 
explains.  “Now,  if  a  cus¬ 
tomer  in  California  wants 
to  add  a  parent  in  Florida  to 
his  account,  we  can  do  that 
very  simply  and  straightfor¬ 
wardly.  It’s  the  same  with  a 
business  that  may  need  to 
change  accounts  for  people 
as  they  are  moved  around 
the  country.  We’re  hitting 
the  sweet  spot  of  what  cus¬ 
tomers  are  asking  for,  which 
is  for  us  to  be  simple  to  do 
business  with.” 

Verizon  Wireless  is  more 
than  likely  saving  its  cus¬ 
tomers  time  and  money  as 
well,  according  to  Gartner 
Inc.  analyst  Phillip  Redman. 

Every  carrier  that  goes 
through  mergers  and  acqui¬ 
sitions  gets  stuck  with  sev¬ 
eral  types  of  billing  systems 
spread  across  the  country, 
Redman  says.  This  leaves 
bills  in  multiple  formats 
and  creates  room  for  error. 
Indeed,  Gartner  estimates 
that  approximately  10%  of 
carriers’  bills  have  errors, 
many  caused  by  inconsis¬ 
tent  systems.  This  is  dif¬ 
ficult  to  monitor,  so  corporate 
customers  waste  a  lot  of 
time  and  money  finding  and 
reporting  errors. 

According  to  Redman, 
“Eliminating  the  chance 
for  errors  by  consolidating 
billing  systems  improves 
accuracy,  creates  higher 
customer  satisfaction  and 
actually  reduces  costs  both 
for  the  enterprise  and  the 
carrier,  which  has  fewer  sys¬ 
tems  to  maintain.”  ■ 


if  The  whole  think- 
ISS  ing  was  that  less  is 
more.  That  means  fewer 
applications  to  manage, 
fewer  rules  of  engagement, 
fewer  touch  points  for  customers. 

AJAY  WAGHRAY,  CIO,  VERIZON  WIRELESS 


COMPUTERWORLD  SEPTEMBER  8,  2008 


SunGard  Availability  Services  help  your  business  move  forward  with 
the  most  advanced  and  widest  choice  of  information  availability  options 
in  the  industry 

|  From  virtualization  to  hot  sites  to  replication  and  vaulting— SunGard  Availability  Services 
does  it  all.  And  it’s  all  we  do.  That  kind  of  focus  helps  ensure  high  availability  of  data, 
applications  and  systems  and  fits  your  needs  and  budget  precisely. 

When  we  partner  with  you,  you  worry  less  about  the  road  ahead.  Here’s  why: 
a  track  record  of  100%  successful  recoveries;  over  60  facilities  with  redundant 
power  connected  to  SunGard's  secure  global  network;  and  more  than  20,000  end- 
user  positions  in  facilities  across  North  America  and  Europe.  SunGard  Availability 
Services— the  information  availability  solution  for  businesses  that  must  run  non-stop. 
Keep  moving,  call  1-800-468-7483  or  visit  www.availability.sungardxom. 


SUNGARD8 

Availability  Services 

Keeping;  People 
and  Information 
Connected. 

■  CAREERS 


Your  intuitive 
response  to  a 
layoff  threat 
may  be  exactly 
wrong. 


£  Janet  Banks  suggests  raising 
your  prolife  when  layoffs  seem 
imminent. 


The  smell  of  fear  is  getting 
stronger  as  the  “R”  word  pops 
up  more  frequently  in  busi¬ 
ness  discussions  and  layoff's 
loom  in  many  companies.  In 
this  month’s  Harvard  Busi¬ 
ness  Review,  Janet  Banks 
and  Diane  Coutu  assert  that 
workers  who  feel  that  their 
jobs  are  threatened  often 
react  in  exactly  the  wrong 
way.  Banks,  a  former  execu¬ 
tive  at  FleetBoston  Financial 
and  Chase  Manhattan  Bank 
who  is  currently  doing  small 
group  facilitation  work  for 
nonprofit  companies,  told 
Kathleen  Melymuka  that 
your  best  strategy  may  not  be 
the  one  that’s  intuitive. 

If  I’m  an  IT  professional, 
what’s  the  single  most  im¬ 
portant  thing  I  can  do  to  keep 
my  job  when  layoffs  seem  to 
be  looming  at  my  company? 
I’d  love  to  say  it’s  your  work 
on  relevant  projects,  but  at¬ 
titude  is  probably  the  single 
biggest  thing  you  can  con¬ 
trol,  and  it  will  impact  how 
you  perceive  yourself  and 
how  others  perceive  you. 

It’s  much  easier  to  deselect 
a  sour,  negative  person  than 
someone  who  is  construc¬ 
tive  and  creative. 

I  don’t  want  to  pigeonhole 
people,  but  tech  work  often 
attracts  introverted  people. 
And  most  business  people 


are  extroverts,  so  they  are 
not  going  to  know  how  an 
introvert  is  thinking.  So  you 
need  to  take  risks  and  put 
yourself  out  [there]  more  — 
offering  constructive  ideas. 

Many  people  hunker  down  and 
keep  a  low  profile  when  layoffs 
threaten.  Your  advice  seems 
to  be  to  do  just  the  opposite. 

Hunkering  down  is  an  illu¬ 
sion.  You  have  the  payroll 
sheet  with  everybody’s 
name  on  it.  Nobody  is  invis¬ 
ible,  and  you  can’t  hide.  Ev¬ 
erything  is  being  assessed: 
every  project,  every  person. 
And  if  you’re  not  visible  in  a 
positive  way,  it’s  easy  to  say, 
“I  won’t  miss  him.” 

You  write  that  it’s  also  valu¬ 
able  to  be  ambidextrous.  What 
does  that  mean  for  an  IT  pro¬ 
fessional?  The  ability  to  play 
multiple  roles.  For  me,  the 
most  important  would  be  a 
capacity  to  identify  with  the 
business  as  opposed  to  just 
the  tech  role.  In  companies 
I’ve  worked  with,  there  have 
been  terrific  examples  of 
people  in  IT  who  really  be¬ 
came  business  leaders.  Art 
Ryan  at  Chase  came  from 
that  world  and  became  CEO. 
But  he  was  always  identified 
with  how  to  make  the  busi¬ 
ness  more  profitable.  That’s 
a  [mind-set]. 

You  stress  the  importance 
of  showing  empathy  for  your 
leaders,  even  if  they  may  be 
planning  to  cut  your  job.  How 
does  that  differ  from  suck¬ 
ing  up?  The  people  who  do 
it  well  do  it  from  an  hon¬ 
est  effort  to  be  supportive 
to  their  boss,  and  it  starts 
with  having  a  relationship 
that  is  built  on  trust  so  you 
can  give  honest  feedback. 
You  can’t  manufacture  that 
in  a  crisis;  it’s  something 
you  need  to  be  working  on 
whether  you’re  worried 
about  your  job  or  not. 


Plan  B  ! 

No  job  protection  plan 
is  foolproof.  As  you  do 
what  you  can  to  keep 
your  job,  it’s  wise  to 
also  prepare  for  the 
worst.  Here  are  some 
things  you  can  do  now: 

■  Determine  what 
you’re  good  at  and  what 

you  enjoy  most. 

-------------------  | 

■  Revisit  Myers-Briggs 

or  other  tests  you’ve 
taken  over  the  years 
to  gain  a  better  un¬ 
derstanding  of  your 
strengths  and  weak¬ 
nesses.  ! 

-------------------  1 

■  Read  self-help  books 

for  inspiration.  ! 

■  Update  your  rdsumd. 

■  Network. 

-------------------  | 

■  Consider  a  creative 
leap  to  a  different 
kind  of  job. 

-------------------  | 

-  Adapted  from  ; 

Harvard  Business  Review  j 

I 

Kissing  up  is  when  people 
hear  you  talking  out  of  two 
sides  of  your  mouth.  You  say 
one  thing  to  the  boss  and 
another  around  the  water 
cooler.  You  can’t  do  that. 
Phony  behavior  is  spotted  a 
mile  away,  so  the  empathy 
has  to  come  from  your  au¬ 
thentic  self. 

What  makes  you  think  this  ap¬ 
proach  to  helping  people  save 
their  jobs  will  work?  There’s 
no  guarantee  that  any  ap¬ 
proach  will  work.  Some¬ 
times  it’s  not  personal  at  all: 
If  a  project  is  gone,  you’re 
gone.  Sometimes  there’s 
nothing  you  can  do  about  it. 
But  at  end  of  the  day,  how  do 
you  want  to  feel  about  your¬ 
self?  Did  you  give  it  your 
best?  ■ 


24  COMPUTERWORLD  SEPTEMBER  8,  2008 


I 


Attend  our  IT  Management  Summit  on  Enterprise  Search 
in  one  of  the  following  cities: 

*  Dallas,  Texas 

Tuesday,  September  23,  2008, 8:45am  to  Noon,  Sheraton  Dallas  Hotel 

Complimentary  registration  available  at:  www.itmanagementsummit.com/registration/dallas 

*  Seattle,  Washington 

Thursday,  September  25,  2008, 8:45am  to  Noon,  The  Fairmont  Olympic  Hotel 

Complimentary  registration  available  at:  www.itmanagementsummit.com/registration/seattle 

New  York,  New  York  - - — 

Thursday,  October  2,  2008, 8:45am  to  Noon,  The  Hilton  New  York 

Complimentary  registration  available  at:  www.itmanagementsummit.com/registration/newyork 


For  additional  information  visit  www.itmanagementsummif.com 
or  contact  Christina  DeAvila  at  508-820*8208. 


Exclusively  sponsored  by 


■  SECURITY  MANAGER’S  JOURNAL !  J.F.  RICE 


Building  a  Security 
Org  From  Scratch 

Coming  in  as  the  security  guru  in  a  com¬ 
pany  with  no  infosec  program  at  all  is  an 
opportunity.  Doing  it  twice  is  even  better. 


I  HAVE  THE  rare  good 
fortune  of  being  in 
a  position  to  help 
build  an  information 
security  organiza¬ 
tion  from  scratch.  I’m  es¬ 
pecially  lucky  because  I’ve 
done  it  before. 

At  my  previous  job,  I 
spent  six  years  building 
an  information  security 
program  where  none  had 
existed.  How  many  of  us 
get  to  do  that? 

It  may  sound  daunting, 
but  let  me  tell  you,  it  was 
immensely  rewarding.  I 
was  able  to  start  with  a 
clean  slate,  building  a 
mature  security  environ¬ 
ment  without  the  distrac¬ 
tion  of  dealing  with  any 
existing  processes  or  in¬ 
frastructure. 

This  time  around,  I  have 
experience  to  lean  on.  For 
example,  I  learned  in  my 
old  job  that  one  of  the  big¬ 
gest  challenges  to  success 
is  negativity,  so  I’m  trying 
to  head  off  resistance  and 
negative  attitudes  while 
racking  up  some  signifi¬ 
cant,  visible  wins  early  on. 
Security  efforts  can’t  bear 
fruit  without  the  coopera¬ 
tion  of  a  large  number  of 
people  from  organizations 
all  across  the  enterprise, 


each  of  which  has  its  own 
priorities  far  removed 
from  what  I  want  to  ac¬ 
complish. 

Dealing  with  software 
vulnerabilities  is  my  first 
big  challenge  in  this  com¬ 
pany.  Determining  which 
systems  need  patching 
and  then  following  up 
with  the  patches  them¬ 
selves  isn’t  very  difficult, 
of  course.  The  challenge 
arises  because  I  don’t  have 
the  authority  to  command 
that  this  be  done.  Instead, 

I  need  to  convince  various 
departments’  technical 
specialists  and  business 
owners  how  important  it  is 
to  patch  the  systems  they 
rely  on,  and  make  it  clear 
why  they  should  spend  a 
significant  amount  of  time 
and  money  to  make  this 
happen.  I’m  sure  you’ve 
seen  this  before  —  the  se¬ 
curity  guru  who  is  respon- 

H  I’m  sure  you’ve 
seen  this  before 
-  the  security  guru 
who  is  responsible 
for  fixing  a  prob¬ 
lem  but  Tacks  the 
authority  to  go  out 
and  patch. 


sible  for  fixing  a  problem 
but  lacks  the  authority  to 
go  out  and  patch. 

So  this  week,  I  took  the 
security  show  on  the  road. 
I’ve  elected  to  put  myself 
out  in  front  of  the  people 
who  need  to  support  and 
fund  this  effort  and  help 
them  understand  what 
needs  to  be  done  and  why. 

Taking  a  top-down  ap¬ 
proach,  I  spent  this  week 
meeting  with  six  senior 
managers  of  various  busi¬ 
ness  units.  These  are 
the  people  who  should 
be  demanding  that  their 
systems  be  patched  regu¬ 
larly,  so  I’m  raising  their 
awareness  of  the  need  for 
vulnerability  management, 
showing  them  reports  on 
the  security  health  of  their 
systems  and  helping  them 
understand  the  risks  as¬ 
sociated  with  unpatched 
systems. 

PATCH  CATCH-UP 

We  have  a  lot  of  catching 
up  to  do  because  most 
of  our  critical  systems 
(yes,  even  the  Internet¬ 
facing  ones)  haven’t  been 
patched  at  all  in  years.  So 
right  now,  although  I’m 
focused  on  catching  up, 
it’s  going  to  be  just  as  im- 


Trouble 

Ticket 

AT  ISSUE:  Most  of 
this  company’s  critical 
systems  haven’t  been 
patched  in  years. 


ACTION  PLAN:  Get 

cooperation  from  various 
departments  by  educat¬ 
ing  and  informing,  not 
threatening. 


portant  to  implement 
a  regular  patching  cycle 
so  that  we  never  fall  be¬ 
hind  again. 

I’ve  had  great  results 
so  far  with  my  education- 
and-advocacy  tour.  I’m 
trying  to  keep  my  mes¬ 
sage  positive,  stressing  the 
benefits,  improvements 
and  returns  to  be  gained 
with  regular  patching, 
while  avoiding  the  use  of 
FUD  to  scare  people  into 
submission.  Even  though 
I  could  tell  them  plenty 
of  stories  about  how  our 
systems  are  being  con¬ 
stantly  attacked,  I’ve  seen 
no  need  to  take  that  route. 
In  fact,  people  have  been 
suggesting  that  we  patch 
everything  as  soon  as  we 
can,  applications  included, 
but  my  focus  right  now 
is  on  patching  the  basic 
operating  systems  and  not 
the  applications  that  run 
on  them. 

I’m  wary  of 
turning  up  the 
throttle  too 
quickly  and  bit¬ 
ing  off  more  than _ 

our  company 

can  chew  right  now.  One 

battle  at  a  time,  please. 

I  know  from  experience 
that  we  have  a  long  road  to 
travel,  and  I’m  settling  in 
for  the  long  haul.  ■ 

This  week’s  journal  is 
written  by  a  real  security 
manager,  “J.F.  Rice,”  whose 
name  and  employer  have 
been  disguised  for  obvious 
reasons.  Contact  him  at 
jf.rice@engineer.com. 


COMPUTERWORLO.COM 


©JOIN  IN 

To  join  in  the  discussions 
about  security,  go  to 

computerworld.com/ 

blogs/security 


U  COMPUTERWORLD  SEPTEMBER  8,  2008 


*) 


RELEVANT 


j 


iMfplifcli 


Get  insight  into  the  hot  topics  of  today  from 
the  experts  -  in  their  own  words.  From  business 
intelligence  to  wireless  technologies,  webcasts 
on  Computerworld.com  bring  every  important 
detail  to  life. 


Check  out  some  of  the  latest  webcasts  at  Computerworld.com: 

•  Gain  a  Faster,  Cheaper  Way  to  Manage  Workload 

•  Why  SaaS  is  Vital  to  Email  and  Web  Security 

•  From  Laggard  to  Leader:  Transforming  the  Data  Center 


www.computerworld.com/webcasts 


The  Voice  of  IT  Management 


IIS 


v:‘ 

■  ^ 


|»B& 


I 


'  <  >j  C  t  . . . 

f  .  — 


Webcasts 


'  Km 

]  Hns 
^  £wi 

^  ■  Stent  fat  j  - - 

j  V*  fk  Jmsfc.feis  imSHmm 


Immm 


'-***«*,  AST— 

■2SSZ,  .fZ?^^********#*** 

sssr*  i, 

i9» s  /  ~ 

itoS^™™*******  •* 

'  **Wfe 


i*>W# 

*»4Wa 


tTTf 

4*n£i«Bir 


f  ffifggg 

AfiS^saS  5* 

ezu 

!l2SSmWt**Sm 


felKfg: 

£?**• 


l*>xriKn,,] 


>fiaBiI*a5asfia>!. 


■  OPINION 

Paul  Glen 


What  Is  a  Job 


WITH  THE  economy  ailing,  the  U.S.  presiden¬ 
tial  election  in  full  swing  and  surveys  show¬ 
ing  cuts  in  next  year’s  IT  budgets,  get  ready  to 
hear  more  and  more  about  jobs.  People  will 
lose  jobs.  Evil  corporations  will  export  jobs.  We  will  need 
more  jobs.  We  will  need  better  jobs.  Not  Mcjobs. 


People  will  become 
unemployed  and  underem¬ 
ployed,  and  they  will  drop 
out  of  the  workforce.  They 
will  go  back  to  school  with 
the  hopes  of  obtaining  bet¬ 
ter  jobs.  The  government 
will  try  to  “create”  jobs 
using  tax  policy,  environ¬ 
mental  policy,  fiscal  policy, 
trade  policy,  labor  policy, 
research  funding,  public 
works  and  a  healthy  dose 
of  prayer. 

The  discussion  will  be 
endless.  But  it  will  skip 
one  important  question: 
What  is  a  job,  anyway? 

The  word  has  become  a 
central  part  of  the  lexicon 
of  personal  finance  and 
career  development.  For 
most  of  us,  it’s  the  primary 
source  of  family  income. 
But  do  we  really  know 
what  it  means? 

I’m  not  an  expert  on 
employment  history,  but  it 
seems  to  me  that  50  years 
ago,  the  meaning  of  a  job 
was  relatively  clear. 

If  you  were  a  man,  you 
joined  a  company  for  an 


indefinite  period,  usually 
assumed  to  be  life.  You 
worked  full  time  and  drew 
a  steady  salary,  and  the 
firm  repaid  your  loyalty. 
When  you  retired,  you  got 
a  pension  and  maybe  even 
health  benefits. 

If  you  were  a  woman, 
the  meaning  of  a  job  was 
probably  more  flexible.  It 
may  have  been  a  career 
or  perhaps  just  something 
to  do  until  you  started  a 
family. 

But  now,  who  knows 
what  a  job  means?  If  you 
worked  for  a  company  for 
five  years  and  it  decided 
to  outsource  your  depart¬ 
ment,  did  you  have  a  job, 
or  was  it  just  a  contract? 

If  you’re  an  independent 

M  It  seems  that  we 
in  IT  -  for  better 
and  worse  -  have 
been  in  the  van¬ 
guard  of  the  cre¬ 
ative  reinvention 
of  employment. 


contractor  with  an  open- 
ended  engagement  with 
a  full-time  client,  do  you 
have  a  job? 

If  you’re  an  employee 
of  a  staffing  firm  that  will 
lay  you  off  as  soon  as  your 
project  ends,  do  you  have 
a  job? 

If  you’re  a  full-time  em¬ 
ployee  of  a  company  and 
you  change  from  being  a 
programmer  to  being  a 
project  manager,  have  you 
changed  jobs? 

The  questions  are  end¬ 
less.  It  seems  that  we  in  IT 
—  for  better  and  worse  — 
have  been  in  the  vanguard 
of  the  creative  reinvention 
of  employment.  Consul¬ 
tants  and  contractors  have 
become  commonplace. 
What  was  once  clear  has 
become  a  jumble. 

Does  this  matter? 

I  think  that  it  does. 
Morale  and  motivation 
are  tied  in  many  ways  to 
whether  our  employment 
relationships  fulfill  our  ex¬ 
pectations.  Employers  and 
employees  come  to  these 


relationships  with  subtle 
and  often  unarticulated 
expectations  that,  if  not 
met,  become  a  source  of 
conflict,  unhappiness  and 
unease. 

While  the  idea  of  the 
1950s  stable  job  lives  on 
and  the  word  job  con¬ 
tinues  to  imply  stability 
and  security,  that  sort  of 
employment  relationship 
has  become  an  endangered  } 
species.  The  reality  is 
much  more  complex  than 
a  three-letter  word  can 

I 

encompass.  That  seems 
to  leave  us  all  on  edge,  j 

always  dissatisfied  with 
the  employment  we  have, 
pining  for  the  fantasy  that 
reality  can  never  achieve. 

So  the  important  } 

question  today  is  not 
whether  you  have  a  job, 
but  whether  you  have  an 
employment  relationship 
that  meets  your  needs  and 
aspirations. 

As  managers,  it’s  past 
time  for  us  to  become 
more  observant  about 

% 

what  our  people  want  and 
need  from  us  and  more  ar-  ' 
ticulate  about  what  we  can  ! 
realistically  offer. 

If  you  want  to  keep  the 
general  malaise  at  bay  and  J 
keep  your  people  focused 
and  motivated,  your  job  in-  \ 
eludes  helping  them  thrive  ‘ 
in  this  new  and  as  yet  un¬ 
named  world.  ■ 

Paul  Glen  is  the  founder  of 
the  GeekLeaders.com  Web 
community  and  author  of 
the  award-winning  book 
Leading  Geeks:  How  to 
Manage  and  Lead  People 
Who  Deliver  Technology 
(Jossey-Bass,  2003).  Contact  ! 
him  at  info@paulglen.com. 


COMPUTERWQRLD  SEPTEMBER  8,  2008 


Your  potential.  Our  pas. 

Microsoft 


alb  v  i\  L 


mm  \ 


smsm 


MICROS 


T  SYSTEM  CENTER.  DESIGNED  FO 


smMmSmmmmM 


Microsoft  System  Center  is  a  family  of 
IT  management  solutions  (including  Operations 
Manager  and  Systems  Management  Server) 
designed  to  help  you  manage  your  mission- 
critical  enterprise  systems  and  applications. 

<'■  .-i:  i-.:' 

y  \\ ...  ; 

Carnival  Cruise  Lines  manages  1,000  shipboard  , ' 
and  land-based  servers  with  System  Center.  That's 


studies  at  DesignedForBig.com 


wtM 


Microsoft 


r  i 

8  m  ,  Percentage  of  large  companies 
/%  that  don’t  support  single-payer 

universal  health  care.  In  a  survey 
conducted  this  spring  by  Watson 
Wyatt  Worldwide  Inc.  and  the  National  Business  Group  on 
Health,  380  of  453  respondents,  who  were  representatives 
of  large  corporations,  said  they  instead  want  to  provide 
workers  with  company-sponsored  health  care  programs. 

L  ^ 


They  Definitely 
Aren’t  Hurting 

Some  of  the  Fortune  1,000  CIOs  with  highest 
levels  of  total  compensation  in  2007: 

SALARY  OTHER  COMPENSATION*  TOTAL 


SOURCE:  JANCO  ASSOCIATES  INC..  FROM  COMPANY  PROXY  STATEMENTS  AND  10-K  FILINGS 
•INCLUDES  BONUSES.  STOCK  OPTIONS.  INCENTIVE  PAY.  PENSION  CONTRIBUTIONS  AND  OTHER 
COMPENSATION 


ASK  A  PREMIER  100  LEADER 


Bruce 

Marcus 


Ilie  CIO  at  The 

McGraw-Hill  Cos.  answers 

questions  about  becoming  a 
leader,  the  economic  outlook 
and  working  things  out 
with  a  difficult  boss. 


How  can  someone  who’s 
interested  in  more  of  a  lead¬ 
ership  role  stand  out  from  his 
peers?  The  broader  perspective 
is  always  a  good  place  to  start. 
Technologists  tend  to  have  deep 
knowledge  and  siloed  perspectives. 
Understand  the  business  objectives, 
and  look  at  how  the  technologies 
you’re  responsible  for  are  and  can 
be  used  to  further  those  objectives. 
This  understanding  provides  a  start¬ 
ing  point  for  discussion  that  tends 
to  differentiate  would-be  leaders. 
Looking  beyond  your  technical  silo 
to  how  all  your  technologist  peers 
can  help  achieve  those 
business  goals  is  part 
of  what  makes  a  leader. 

Showing  the  way  out  of 
endless  abstract  debates 
about  what’s  the  best 
technical  approach 
toward  a  solution  that’s 
good  enough  for  the  business  pur¬ 
pose  helps  as  well.  Your  customers 
will  likely  appreciate  the  perspective, 
and  your  leadership  may  well  rec¬ 
ognize  your  ability  to  communicate 
in  ways  that  tie  technology  goals  to 
business  and  customer  impact. 

8  was  just  starting  to  regain 
some  confidence  in  the  IT 
industry  when  the  economy 
started  to  go  south  a  few 
months  ago.  Is  IT  going  to  get 
hit  hard  by  this  downturn? 

Yes,  but  it’s  not  likely  to  be  as  big 
a  hit  as  in  the  previous  downturn. 

IT  organizations  are  generally  now 
more  efficient  and  focused  on 


higher-value  skills  than  previously. 
And  more  and  more  technology  is 
focused  on  the  revenue-generating 
side  of  the  business  than  ever  be¬ 
fore.  Businesses  seem  to  be  moving 
cautiously  toward  adjusting  IT  staff¬ 
ing  in  this  downturn. 

I’ve  had  some  run-ins  with 
my  boss,  who  becomes  very 
defensive  if  anyone  suggests 
other  ways  of  doing  things. 
His  attitude  seems  petty 
to  me,  but  I’m  the  one  who 
gets  labeled  “negative”  all 
the  time.  What  should  I  do? 

I’d  take  a  good  look 
at  how  you’re  raising 
suggestions.  With 
some  bosses,  being 
challenged  in  a  room 
full  of  other  people  is 
usually  guaranteed  to 
go  nowhere  and  earn 
you  a  negative  label.  A  one-on-one 
session  may  help  your  boss  put 
aside  her  or  his  ego  and  listen. 
Sometimes,  a  short  written  sugges¬ 
tion  -  sent  only  to  your  boss  (same 
ego  issue)  may  help  open  the  door. 
Sometimes,  when  there  are  com¬ 
peting  notions  about  how  to  move 
forward,  abstract  discussion  isn’t 
helpful,  and  only  real-world  experi¬ 
ence  can  get  to  a  conclusion.  Even 
when  the  winning  idea  isn’t  yours, 
be  as  energetic  about  realizing  it  as 
you’d  be  if  it  were  your  own.  That 
lends  credibility  -  “It  wasn’t  Tom’s 
idea,  but  he  worked  the  hardest  to 
make  it  happen”  -  which  is  critical  to 
getting  suggestions  taken  seriously. 


r=ssr  COM  | 

O  QUESTION? 

If  you  have  a  question 
for  one  of  our  Premier 
100  IT  Leaders,  send 

ittoaskaleader@ 

computerworld.com, 

I  and  watch  for  this  . 
column  each  month. 


40  COMPUTERWORLD  SEPTEMBER  8,  2008 


PAGE  COMPILED  BY  JAMIE  ECKLE. 


IT  careers 


Co-Branded 

EMAIL 

BLASTS 


Reach  your  target  audience 
of  professional  IT  job  seek¬ 
ers  with  Computerworld’s 
Co-Branded  Email  Blasts. 
This  unique  program  allows 
you  to  choose  your  criteria 
of  1 00%  opt-in  subscribers 
by  geography,  company 
size,  job  title  and  industry. 

Call  Dawn  Cora  at 
800-762-2977  for  details! 

COMPOTIRWORLD 


With  35  branch  offices  located 
across  the  US,  COMSYS  is 
actively  recruiting  for  the 
following  positions.  Business 
Analyst-  metro  Warren,  NJ- 
Code  #  WA140  SAS 

Programmer  -  metro  New  York, 
NY-  Code  #  NY110  Statistical 
Database  Analyst-  metro 
Portage,  Ml-  Code  # 
PO160Statistical  Database 
Analyst-  metro  Portage,  Mi- 
Code  #  PO170  Programmer 
Analyst  -  metro  Scottsdale,  AZ  - 
Code  #  SCI  00  Roving 
employment  to  varying  jobsites 
throughout  the  US.  Please  refer 
to  appropriate  job  code  when 
submitting  resume  to:  COMSYS, 
Attn.  Nancy  Theriault,  15455  N. 
Dallas  Pkwy.,  Ste  300,  Addison, 
TX  75001.  EOE./MF/DV 


Computer  &  Information  Systems 
Manager  (2  Positions)  w/Masters 
or  foreign  equiv  in  Comp  Sci  or 
Engg  &  1  yr  exp.  ‘Will  accept 
Bach  or  foreign  equiv  &  5  yrs 
progressive  work  exp  in  lieu  of 
Masters  or  foreign  equiv  &  1  yr 
exp.  Manage,  plan,  dsgn,  dvlp, 
integrate  &  implmt  Unix  based 
applies  on  OOP  concept,  Java, 
JSP,  Servlet,  JDBC,  EJB,  RMI, 
Java  Script,  CORBA.  Analyze 
reqmts  &  determine  feasibility  of 
dsgn.  Define  data  architecture  & 
implmt  logical  &  physical  data 
model  using  Rational  Rose.  Exp 
as  Sr.  Software  Engineer 
acceptable.  Supv  3  Computer 
Programmers.  Mail  resumes  to 
STG,  Inc,  910  Bergen  Ave,  Ste 
202,  Jersey  City,  NJ  07306.  Job 
loc:  Jersey  City,  NJ  or  any 
unanticipated  Iocs  in  US. 


Programmer  Analyst,  BNP 
Paribas  North  America,  Manh. 
Design  &  implement  Data  Access 
Layer  using  JAVA,  J2EE  Spring, 
WebServices,  SQL,  Axis  & 
WebLogic.  Optimize  use  of 
Hibernate  on  project.  Provide 
technical  support  to  other  team 
members  on  Hibernate.  Write 
technical  documentation  & 
Hibernate  development 

guidelines.  Participate  in 
technical  reviews  of  technical 
architecture.  Min  of  Bachelor's 
or  foreign  equivalent  degree  in 
Electronic  Engineering  or 
Computer  Science  +  5  yrs  exp 
req'd  in  job  offered  or  as  a 
Software  Engineer.  Send  resume 
to  careers@americas.bnpparibas.com 
and  refer  to  job  code  Pill  in 
subject  line. 


Programmer  Analyst  w/2  yrs 
exp  to  analyze,  dsgn,  dvlp,  test 
&  implmt  interfaces  &  custom 
solutions  using  Developer  2000, 
PL/SQL,  SQL*Loader,  SQL* 
Plus  &  Oracle  Discoverer. 
Implmt  &  customize  Oracle 
Applies  on  Sun  Sparc  Solaris 
(Unix)  operating  systms.  Mail 
resumes  to:  R.J.  Ventures  Inc., 
15  East  Germantown  Pike, 
Norristown,  PA  19401.  Job  Loc: 
Norristown,  PA 


IT-Manager  &  Programmer 
Analyst  (New  York)  NY:  Dvlp 
Computer  applications  software  / 
specialized  utility  progrms.  for  IT- 
Manager  masters  w/exp  or  bach 
w/5  years  exp.  &  for  programmer 
analyst  2  yrs  exp  reqd.  Respond 
to  hrd,  Systec  International,  inc., 
575,  8th  avenue,  ste.  #  2200, 
New  York.NY- 10018. 


Computer  &  Information  Systems 
Manager  w/Masters  or  for  equiv 
in  Comp  Sci  or  Engg  &  1  yr  exp. 
*Will  accept  Bach  or  for  equiv  &  5 
yrs  progressive  work  exp  in  lieu 
of  Masters*  or  for  equiv  &  1  yr 
exp.  Manage,  plan,  organize  & 
implmt  object  oriented  enterprise 
applies  using  .NET  Framework, 
C#Winform,  Win  Svcs,  ASP.NET, 
SQL  Server,  IIS,  HTML,  Java 
Script  &  XML.  Architect,  dsgn, 
dvlp  &  test  applies  using  Visual 
Studio.NET.  Exp  as  Lead 
Developer  acceptable.  Supv  3 
Consultants.  Mail  res  to  Open 
Systems  Technologies,  462  7th 
Ave,  15th  FI,  NY,  NY  10018.  Job 
loc:  NYC. 


Didn’t  find  the 
IT  career 
that  you  were 
looking  for? 


Check  back  with  us  weekly 
for  fresh  listings  placed 
by  top  companies 
looking  for  skilled 
professionals  like  you! 


iTjcareers 


/ 


Place  your 
legal  ads  here! 


\ 


Contact 
Dawn  Cora  at: 


800. 762.2977 

or  email 

itcproduction 

©itcareers.net 


ucareers 


Programmer  Analyst  w/Bach  or 
foreign  equiv.  in  CS  or  Engg  or 
Math  &  1  yr  exp  to  analyze,  dvlp 
&  test  telecom  apples  incl  Voice 
Mail  sys,  IVR  sys,  using  C,  C++, 
VC++,  VB,  ASP,  HTML,  DHTML, 
XML,  TCP/IP.  SMTP  &  MS  SQL. 
Identify  current  operating 
procedure  &  clarify  prgms.  Mail 
res:  Eagle  Teleconf.  Serv  Inc. 
207  W.  Washington  St., 
Rushville,  IL  62681.  Job  Loc: 
Rushville,  IL  or  in  any 
unanticipated  loc  in  USA. 


Searching  for  diverse  IT  Talent? 

<D 

Let  Computerworld  IT  careers  put  your  recruitment 

<D 

message  in  front  of  over  1,400,000 

V- 1 

qualified  IT  professionals! 

o 

Contact  Dawn  Cora  for  details 

or  email  itcproduction@itcareers.net  or 
call  800  762  2977 

SEPTEMBER  8,  2008  C0MPUTERW0RLD 


TRUE  TALES  OF  IT  LIFE  AS  TOLD  TO  SHARKY 


j  It  Would’ve  Helped 

;  This  pilot  fish  writes  custom 
!  software  for  his  company  and 
■  supports  its  users  at  remote 
!  sites.  So  when  a  user  con- 
;  tacts  him  to  say  the  software 
J  has  suddenly  stopped  work- 
I  ing,  fish  is  right  on  it.  “For- 
I  tunately,  the  user  enclosed 
!  a  screenshot,  though  the 
|  information  from  the  screen- 
j  shot  was  useless,”  says  fish. 

!  “I  asked  the  user  to  attach 
i  the  log  file  that  my  applica¬ 
tion  generates  if  problems 
;  occur.”  But  the  log  file  reveals 
J  nothing,  and  fish  begins  to 
*  get  concerned.  He  asks  the 
!  user  to  write  down  what  he 
;  did,  step  by  step,  just  before 
I  the  error  occurred.  User  does, 
!  and  fish  runs  through  the 
\  steps  on  his  end  without  any 


problems.  Then  fish’s  boss 
gets  involved  and  tells  fish 
to  start  checking  with  users 
at  other  sites.  Several  hours 
into  that  process,  fish  calls 
the  user  again  to  get  more 
information  on  the  problem 
and  have  him  try  one  specific 
work-around.  “Oh,”  says  user, 
once  fish  gets  him  on  the 
phone,  “the  tech  guys  just 
took  it  away.  All  of  my  other 
programs  had  stopped  work¬ 
ing  and  the  PC  crashed  right 
after  my  last  e-mail  to  you. 
They  think  I  may  have  had  a 
virus.  Should  I  have  called?” 

Just  Following  Orders 

Phone  company  tech  shows 
up  at  this  business  to  install 
two  new  high-availability 
routers,  replacing  a  single 


older  model.  “The  plan  was  to 
leave  the  old  router  in  place 
as  backup,  to  be  removed 
after  60  days,”  says  a  pilot 
fish  in  the  know.  “The  office 
and  all  300  users  were  soon 
up  on  the  new  routers.”  Flash 
forward  60  days:  The  very 
same  tech  shows  up,  walks 
past  all  300  users  and  pro¬ 
ceeds  to  the  switch  room  to 
decommission  the  old  router. 
“However,  the  offshore  group 
responsible  for  creating  the 
decom  order  made  a  mistake, 
and  the  tech  proceeded  to 
decom  the  two  new  routers,” 
fish  says.  “Later  that  evening, 
when  the  configurations  and 
circuit  connections  were  re¬ 
applied  and  the  routers  were 
back  up,  tech  was  informed 
that  he’s  banned  from  that 
customer  site  for  life.” 

Who  Knew? 

Pilot  fish  works  the  late  shift, 
so  he’s  not  due  at  the  office 
until  10  a.m.  But  at  8:45  a.m., 
he  gets  a  call  from  a  col¬ 
league:  The  server  is  dead, 


the  root  disk  is  corrupt,  and 
he’s  going  to  have  to  arrange 
a  replacement  disk  and  recov-  ! 
ery.  OK,  fish  figures,  he’s  got 
it  covered;  no  need  to  come  in 
early.  “When  I  arrived  on-site,  j 
I  went  to  the  computer  and 
rebooted  it.  It  started  clean 
immediately,  and  we  got  ev¬ 
erything  up  and  running  with 
no  errors,”  says  fish.  “My  col-  ; 
league  then  had  to  send  out 
e-mails  saying,  ‘Whoops,  the 
server  is  now  up,  and  cancel 
the  engineer.’  ” 

■  Sharky’s  up  and  running  and  1 
waiting  for  your  true  tale  of  IT  J 

life.  Send  it  to  me  at  sharky@ 
computerworld.com.  I’ll  send 
you  a  stylish  Shark  shirt  if  I 
use  it.  i 

l 

I 


COMPUTERWORLD.COM 


O  NEED  TO  VENT  YOUR  SPLEEN? 

Toss  some  chum  into 
the  roiling  waters  of 
Shark  Bait.  It's  therapeutic! 

sharkbait.computerworld.com. 


©CHECKOUT  Sharky’s  blog,  browse  the 
Sharkives  and  sign  up  for  Shark  Tank  home 
delivery  at  computerworld.com/sharky. 


■  COMPANIES 
IN  THIS  ISSUE 

Page  number  refers  to  page  on  which 
story  begins.  Company  names  can  also 
be  searched  at  computerworld.com 


ACS  Healthcare  Solutions . 11 

Affiliated  Computer  Services  Inc . 11 

Alabama  Political  Science  Association . 16 

Alcatel-Lucent . 8 

Ameriprise  Financial  Inc . 40 

Apgar  &  Associates  LLC . 11 

Apple  Inc . 9 

Asustek  Computer  Inc . 6 

Austin  Energy. . 19 

BAE  Systems  Inc . 8 

Bank  of  America  Corp . 40 

Best  Buy  Co . 40 

BT  Group  PLC . 8,19 

CAInc . 6 

California  Credit  Union  League . 6 

Captaris  Inc . 6 

Centers  lor  Medicare  &  Medicaid  Services . 11 

ClearApp  Inc . 6 

Clin rate  Savers  Computing  Initiative . 19. 23 

Diebold . 16 

Digimatlonlnc . 4 

Directions  on  Microsoft . 9 

FedEx  Corp . 40 

First  National  of  Nebraska . 19 

Forrester  Research  Inc . 9 

Fujitsu  Services  Holdings  PLC . 8 

Gartner  Inc . . . . 6,9,32 

General  Mills  Inc . ; . ...40 


Google  Inc . 2,8,9,44 

Healthcare  Information  and 

Management  Systems  Society. . 11 

HIPAA  Solutions  LC . 11 

Honeywell  International  Inc . 40 

Intel  Corp. . . 6 

International  Association  of 

Outsourcing  Professionals . 4 

iRobot  Corp . 8 

Iron  Mountain  Inc . 23 

Janco  Associates  Inc . 40 

Loyola  University . 4 

Marriott  International  Inc . 22 

Memorial  Hermann  Healthcare  System . 11 

Microsoft  Corp . 2, 4,9 

Monsanto  Co . 23 

Mozilla  Corp . 9 

Mphasis  Ltd . 8 

National  Business  Group  on  Health . 40 

National  Science  Foundation . 14 

Net  Applications  Inc . 9 

Office  of  Civil  Rights . 11 

Open  Text  Corp . 6 

Opera  Software  ASA . 9 

Oracle  Corp . 6 

Other  World  Computing . 19 

Piedmont  Hospital . 10 

PriceWaterhouseCoopers . 11 

Providence  Health  &  Services . 10, 11 

Qualcomm  Inc . 22 

Qumranetlnc . 6 

Red  Hat  Inc . 6 

Salesforce.com  Inc . 44 

SAP  AG . 4 

Sony  Corp . 8 

Stanford  University . 8 


SunGard  Availability  Services  LP . 4 

The  Dow  Chemical  Co . 40 

The  Green  Grid . 19,23 

The  Home  Depot  Inc . 40 

The  McGraw-Hill  Cos . 40 

The  PNC  Financial  Services  Group  Inc . 40 

Tidewater  Inc . 4 

Tufts  University . 8 

U.S.  Army  Research  Laboratory . 8 

U.S.  Consumer  Product  Safety  Commission . 8 

]  U.S.  Defense  Advanced 

j  Research  Projects  Agency . 8 

U.S.  Department  of  Energy . 23 

U.S.  Department  of 

Health  and  Human  Services . 10, 11 

Verizon  Wireless . 32' 

Virgin  Entertainment  Group  Inc . 9 

Vision-Box  Co . 8 

Watson  Wyatt  Worldwide  Inc . 40 

WellPoint  Inc . 40 


Akamai . 29 

www.akamai.com/10years 

Fujitsu  Computer  Systems  Corporation ...  27 

us.fujitsu.com/computers/reliablestorage 

Hewlett-Packard  ProCurve . 13 

ProCurve.com/Choice 

Hewlett-Packard  ProLiant . C4 

hp.com/go/dependable14 

IBM  Express  Seller . C2 

ibm.com/systems/uptime 

IBM  IT  Campaign . 20-21 

ibm.ccm/green/datacenter 

IBM  IT  Campaign . 24-25 

ibm.com/green/data 

Inter  Systems . C3 

lnterSystems.com/Connect15A 

IT  Management  Summit . 35 

www.itmanagementsummit.com 

Microsoft  System  Center . 39 

DesignedF0rB1g.com 

Microsoft  Unified  Communication . 31 

microsob.com/voip 

Microsoft  Windows  Server  2008  . 5 

serverunieashed.com 

NEC . 7 

www. necus.com/necip 

Novell . 17 

moreinterop.com 

SAS . 15 

www.sas.com/ostrlches 

SunGard  Availability  Services . 33 

www.availability.sungard.com 


'tills  Ind**  I,  provided  m *  *»  eddttionel  service.  Tie  potohlwt 
does  not  assume  enj  Hehfilty  for  errors  or  omisskms. 


F  ^ca!  postage  pa.d  at  Framingham.  Mass,  and  otter  mailing  offices.  Posted  under  Canadian  International  Publication  agreement  PM40063731.  CANADIAN  POSTMASTER:  Please  return  undeliverable  copy  to  PO  Box  1632  Windsor  Ontario  N9A  7C9  Comouterworld  (ISSN  non 
<84  i)  is  putted  weekly  except  or  a  single,  combined  Issue  the  first  two  weeks  or  July  and  the  last  two  weeks  of  December  by  Computerwortd,  Inc.,  1  Speen  Street,  Box  9171,  Framingham.  Mass.  01701-9171  Copyright  2008  by  Computerworld  Inc  All  rights  reserved  Comouterworld  can  be 
’  3Sfcd  m  miC™ a"d  mfcr0fichil  th,ou°h  d™a'silv  Micrafllms  ,nc"  300  N.  Zeeb  Road.  Ann  Arbor  Mich.  48106.  Computerworld  is  indexed.  Back  issues,  if  available,  may  be  purchased  from  the  circulation  department.  Photocopy  rights:  permission  to  photocopy  for  internal  or  personal 

*  - - if  B  9™'ed  Computerwortd  Inc.  for  libraries  and  other  users  registered  with  the  Copyright  Clearance  Center  (CCC),  provided  that  the  base  fee  of  $3  per  copy  ot  the  article,  plus  50  cents  per  page  is  paid  directlv  to  Convnnh 

SJSvS®  C  rnf' 27  Conflres3  St" Salem' Mass-  °1970' Repnn,s  (minimum  100  copies)  and  permission  to  reprint  may  be  purchased  from  Erik  Eberz,  Computeiworld  Reprints  c/o  The  YGS  Group8  Greenfield  Corporate  Center 

ec  eu  v  thin  6 )  days  of  isoue  date,  Subscr  iption  rates.  $5  per  copy.  U.S.  -  $99.99  per  year.  Canada  -  £130  peryear:  Central  &  So.  America,  $250  per  year;  Europe  -  $295  per  year  all  other  countries  -  $295  ner  vear  Suhsrnn 
lions  call  toll-tree  (888)  559-7327  POSTMASTER:  Sand  Form  3579  (Change  of  Address)  to  Computerworld,  PO  Box  3500,  Northbrook.  III.  60065- 3500!  CUr°P6  ^S0Pe'Vea«»°^r  countries  $295  per  year.  Subscnp- 


ABM 


I 

* 


COMPUTERWORLD 

HEADQUARTERS 

P.O.  Box  9171, 1  Speen  Street 
Framingham,  MA  01701-9171 
(508)879-0700 
Fax  (508)  875-4394 


President/Publisher/CEO 

Matthew  J.  Sweeney 
(508)271-7100 

Executive  Assistant  to  the 
President/Publisher/CEO 

Diana  Cooper 
(508)820-8522 

Vice  President/Publisher 
integrated  Programs  &  Events 

John  Amato 
(508)820-8279 

Vice  President/ 

General  Manager  Online 

Martha  Connors 
(508)620-7700 

Vice  President,  Marketing 

Matt  Duffy 
(508)820-8145 

Vice  President,  Custom  Content 

Bill  Laberis 
(508)820-8669 

Vice  President,  Human  Resources  Fax  (508)  626-8524 

Julie  Lynch 

(508)820-8162  ! 

f 

Executive  Vice  President,  Senior  Sales  Operations  Manager 

!  ■  NEW  ENGLAND  STATES 
!  Vice  President, 
l  Integrated  Programs 

•  Deborah  Crimmings  (508)  271-7110 

«  Senior  Sales  Associate,  1 

!  Integrated  Programs 

|  Jess  Roman  (508)  271-7108 
J  Mailing  Address 

j  P.O.  Box  9171,1  Speen  Street 
!  Framingham,  MA  01701 
;  Fax  (508)  270-3882 


<  ■  METRO  NEW  YORK 

i  8  EASTERN  CENTRAL 
J  STATES/INDIANA 

•  Vice  President, 

!  Integrated  Programs 

I  Peter  Mayer  (201)  634-2324 

{  Senior  Sales  Associate, 
i  Integrated  Programs 

!  John  Radzniak  (201)  634-2323 

1 

>  Mailing  Address 

‘  650  From  Road,  Suite  225 
J  Paramus,  NJ  07652 

*  Fax  (201)  634-9289 


Strategic  Programs 

Ronald  L.  Milton 
(508)820-8661 

Vice  President/Publisher 
Computerworld.com 

Gregg  Pinsky 
(508)271-8013 

Executive  Vice  President/COO 

Matthew  C.  Smith 
(508)820-8102 

Vice  President/Editorial  Director 

Don  Tennant 
(508)620-7714 

Vice  President,  Circulation 

Debbie  Winders 
(508)820-8193 


International  Data  Group 
Chairman  of  the  Board 

Patrick  J.  McGovern 

CEO, 

IDG  Communications 

Bob  Carrigan 


Dawn  Cora  (508)  820-8133 

■  NORTHWESTERN  STATES 

■  BAY  AREA 

Vice  President, 

Display  Programs 

Jim  Barrett  (415)  978-3306 

Senior  Sales  Associate, 
Integrated  Programs 

Chris  Da  Rosa  (415)  978-3304 
Mailing  Address 

501  Second  Street,  Suite  114 
San  Francisco,  CA  94107 
Fax  (415)  543-8010 

■  SOUTHWESTERN  STATES 

■  CENTRAL  STATES 
Vice  President, 

Integrated  Programs 

Bill  Hanck  (949)  442-4006 

Senior  Sales  Associate, 
Integrated  Programs 

Emmie  Hung  (415)  978-3308 
Mailing  Address 

19200  Von  Karman  Avenue 
Suite  360,  Irvine,  CA  92612 
Fax  (949)  476-8724 


President/Publisher/CEO 

Matthew  J.  Sweeney  (508)  271-7100 
Fax  (508)  270-3882 


Vice  President/Publisher, 
Integrated  Programs  &  Events 

John  Amato  (508)  820-8279 
Fax  (508)  626-8524 


Computerworld  is  a  business  unit 
of  IDG,  the  world’s  leading  technol¬ 
ogy  media,  research  and  events 
company.  IDG  publishes  more  than 
300  magazines  and  newspapers 
and  offers  online  users  the  largest 
network  of  technology-specific 
sites  around  the  world  through 
IDG.net  ( www.idg.net ),  which 
comprises  more  than  330  targeted 
Web  sites  in  80  countries.  IDG 
is  also  a  leading  producer  of  168 
computer-related  events  worldwide, 
and  IDG's  research  company,  IDC, 
provides  global  market  intelligence 
and  advice  through  51  offices  in  43 
countries.  Company  information  is 
available  at  www.idg.com. 


■  SOUTHEASTERN  STATES 
Vice  President, 

Integrated  Programs 

Lisa  Ladle-Wallace  (904)  284-4972 

Mailing  Address 

5242  River  Park  Villas  Drive 
St.  Augustine,  FL  32092 
Fax  (800)779-8622 

Senior  Sales  Associate, 
Integrated  Programs 

Jess  Roman  (508)  271-7108 
Mailing  Address 

P.O.  Box  9171, 1  Speen  Street 
Framingham,  MA  01701 
Fax  (508)270-3882 


I 


CIRCULATION 
Circulation  Manager 

Diana  Turco  (508)  820-8167 


PRODUCTION 

Vice  President,  Production 

Carolyn  Medeiros 

Production  Manager 

Kim  Pennett 

Print  Display  Advertising 

(508)820-8232 
Fax  (508)  879-0446 

DISTRIBUTION 
Director  of  Distribution  and 
Postal  Affairs  Bob  Wescott 

STRATEGIC  PROGRAMS 
AND  EVENTS 
Vice  President,  Business 
Development  John  Vulopas 
Vice  President,  Strategic 
Programs  &  Events  Ann  Harris 
Vice  President,  Event 
Marketing  and  Conference 
Programs  Derek  Hulitzky 
Director,  Event  Management 
Michael  Meleedy 

Executive  Programs  Specialist 
Executive  Assistant  Kelly  McGill 
Fax  (508)  626-8524 

ONLINE  ADVERTISING 

Vice  President/Associate  Publisher 

Sean  Weglage  (415)  978-3314 
Fax  (415)  543-8010 

Online  Sales  Director,  East  Coast 

James  Kalbach  (610)  971-1588 

Online  Sales  Managers 

Farrah  Forbes 
(415)978-3313 
Fax  (415)  543-8010 

Jennell  Hicks 
(415)978-3309 
Fax  (415)  543-8010 

Matthew  Wintringham 
(508)270-3882 
Fax  (508)  270-3882 

Account  Services  Director 

Bill  Rigby  (508)  820-8111 
Fax  (508)270-3882 

Online  Sales  Assistant 

Joan  Olson  (508)  270-7112 
Fax  (508)  270-3882 


IT  CAREERS 

Senior  Sales  Operations  Manager 

Dawn  Cora  (508)  820-8133 
Fax  (508)626-8524 


LIST  RENTAL 
Postal  and  E-mail 

Rich  Green  (508)  370-0832 
rgreen@idglist.com 
Mailing  Address 

IDG  List  Services,  P.O.  Box  9151 
Framingham,  MA  01701-9151 
Fax  (508)370-0020 


FRANKLY  SPEAKING 


Under  the  Chrome 


GOOGLE  CHROME?  Hold  that  thought. 

First,  let’s  say  your  organization  has  confiden¬ 
tial  data  —  Social  Security  numbers,  credit  card 
transactions,  customer  sales  information,  anything 
like  that.  Would  you  rather  keep  it  in  your  data  center  or  have 
it  sitting  on  a  user’s  laptop? 


That’s  easy:  You  want  it 
safe  in  the  data  center.  But 
that  makes  the  data  much 
less  convenient  to  an  em¬ 
ployee  who  might  have 
used  it  to  analyze  a  trend, 
identify  fraud  or  close  a 
sale.  It’s  a  trade-off;  to  put 
that  data  to  its  best  use, 
you  might  have  to  give  up 
some  control  and  entrust 
that  user  with  the  data. 

Now  what  about  this: 
Say  you’re  going  to  hand 
over  a  critical  chunk  of 
your  IT  infrastructure  to 
an  outsider.  Where  do  you 
draw  the  line?  At  turning 
over  all  IT  operations  to 
an  outsourcer?  At  letting 
Salesforce.com  own  your 
sales  force  automation?  At 
bringing  in  a  consultant 
to  run  your  online  retail 
operation?  At  third-party 
Web  hosting?  At  leased  T1 
network  lines? 

Chances  are  your  com¬ 
fort  zone  ends  somewhere 
in  the  neighborhood  of 
Salesforce.  Software  as  a 
service  still  makes  many 
IT  people  a  little  queasy. 
Will  the  advantages  be 
worth  having  an  outsider 
so  involved  in  everything 


that  your  sales  users  do? 
Maybe  —  but  that  re¬ 
quires  a  lot  of  trust,  and 
it’s  not  a  decision  that 
anyone  in  IT  should  make 
lightly. 

Which  brings  us  back  to 
Chrome,  the  Web  browser 
that  Google  released  in 
beta  form  last  week  (see 
story,  page  9). 

Much  ink  and  many 
electrons  have  been 
spilled  over  the  fact 
that  Chrome  is  fast  and 
simple  and  designed  to 
run  Web  applications 
well  (especially  Google’s 
Web  applications),  that  it 
won’t  let  one  bad  Web  site 
crash  the  whole  browser, 
that  it  grabbed  a  1%  share 
of  Web  browsing  in  less 
than  a  day. 

And,  of  course,  that  it’s 

H  Google  doesn’t 
see  Chrome  as  just 
another  browser. 
It’s  more  like  the 
front  end  for  a 
Web-browsing 
software-as-a- 
service  offering. 


Google’s  “Windows  kill¬ 
er”  (and  good  luck  with 
that  one,  kids). 

But  it’s  really  just  a 
Web  browser,  right?  No. 
At  least,  not  the  way 
we’ve  thought  about  Web 
browsers  before. 

Most  browsers  send 
HTTP  messages  to  far-off 
Web  servers,  which  re¬ 
spond  with  HTML  pages. 
Chrome  spends  nearly  as 
much  time  phoning  home 
to  Google  as  it  does  talk¬ 
ing  to  other  Web  servers. 

Type  in  a  Web  address 
that  doesn’t  exist  and 
Chrome  will  send  it  to 
Google  for  help  finding 
the  right  address. 

Type  in  an  address  that 
Google  has  flagged  as  a 
phishing  or  malware  site 
and  Chrome  will  send  an 
obfuscated  version  of  the 
address  to  Google  to  get 
more  information  about 
the  risk. 

Type  anything  at  all 
into  the  address  bar  and 
Chrome  will  send  the 
keystrokes  to  Google  for 
help  suggesting  what  you 
may  be  looking  for. 

And  that  doesn’t  in¬ 


clude  the  usage  statistics 
and  other  information 
that  Chrome  sends  home  | 

for  Google  to  use  “in 
order  to  operate  and  im¬ 
prove  Google  Chrome  | 

and  other  Google  ser¬ 
vices,”  according  to 
Google’s  privacy  notice 
for  Chrome.  ] 

You  can  turn  much  of 
that  phoning-home  off,  or 
at  least  reduce  it.  But  it’s 
clear  that  Google  doesn’t 
see  Chrome  as  just  an¬ 
other  browser.  It’s  more 
like  the  front  end  for  a 
Web-browsing  software- 
as-a-service  offering. 

Feeling  queasy?  J 

Relax.  Right  now, 

Chrome  is  a  beta  with  sig-  * 
nificant  security  problems  | 
yet  to  be  addressed.  By 
definition,  it’s  not  ready 
—  that’s  what  beta  means,  j 
Bugs  and  security  1 

holes  will  be  fixed.  But 
Chrome’s  basic  business 
model  won’t  change.  J 

So  when  you  start 
evaluating  it  —  and  you 
should  —  don’t  just  test 
how  well  it  serves  up  Web  \ 
applications,  how  robust 
it  is  or  whether  it  really  is 
a  better  browser. 

Think  about  this: 

Are  you  ready  to  trust 
a  software-as-a-service 
model  for  just  about  ev¬ 
erything  your  users  do? 

Because  that’s  Google 
Chrome.  ■  | 

Frank  Hayes  is  Computer- 
world’s  senior  news 
columnist.  Contact  him 
at  frank_hayes@ 
computerworld.com. 


44  CQMPUTERWORLB  SEPTEMBER  8,  2008 


Work  with  InterSystems 


The  fastest  way  to  have  a  connected  workplace. 


Work  with  InterSystems  Ensemble®  software  to  raise 
productivity  and  lower  costs. 

Ensemble  is  a  rapid  integration  and  development 
platform  that  makes  it  much  easier  to  connect  applications, 
processes,  and  people.  IT  managers  who  have  switched 
from  other  integration  products  report  they  can  finish 
projects  in  half  the  time  with  Ensemble. 

For  your  future  development  efforts,  if  you  embed 
Ensemble  you  can  create  a  new  class  of  applications  that 
are  connectable.  Plus,  you'll  be  able  to  enhance  legacy 
applications  with  adaptable  workflow,  browser-based  user 


interfaces,  rules-based  business  processes,  dashboards, 
and  other  innovations  -  without  rewriting  your  code. 

Ensemble's  technology  stack  includes  the  world’s 
fastest  object  database  -  InterSystems  Cache®.  Cache’s 
lightning  speed,  massive  scalability,  and  rapid  development 
environment  give  Ensemble  unmatched  capabilities. 

For  30  years,  we've  been  a  creative  technology 
partner  for  leading  enterprises  that  rely  on  the  high 
performance  of  our  products.  Ensemble  and  Cache  are 
so  reliable  that  the  world's  best  hospitals  use  them  for 
life-or-death  systems. 


ImterSystems 

See  product  demonstrations  at  InterSystems.com/Connectl5A 


©  2008  InterSystems  Corporation.  All  rights  reserved.  InterSystems  Ensemble  and  InterSystems  Cachi  are  registered  trademarks  of  InterSystems  Corporation.  Other  product  names  are  the  trademarks  of  their  respective  vendors.  9-08  Workl5  CoWo 


ALTERNATIVE  THINKING  ABOUT  SERVER  MANAGEMENT: 


> maMjga 


room  to  manage  your  servers 


wmmim 


The  HP  ProLiant  DL385  G5  Server,  featuring  efficient  Quad-Core  AMD  Opteron™  processors,  lets  you  manage  it  from  your  office  in 
San  Diego  while  it  sits  in  Boston.  Remote  Management  (iL02)  lets  you  control,  reboot  and  troubleshoot  from  practically  anywhere, 

even  when  the  server  is  off. 

Technology  for  belter  business  outcomes. 


fri-iim  . . . 

AMDP 

Opteron 


Smart  (PN:  464211-005) 

•  2  Quad-Core  AMD  Opteron™  processors 

•  Supports  small  form  factor,  high-performance 
SAS  or  low-cost  SATA  hard  drives 

•  Redundant  Power 

•  Integrated  Lights-Out  (iL02),  Systems 
Insight  Manager,  SmartStart 

Get  More: 

Smart  24x7,  4  hour  response,  3  years 

(PN:  UE894E)  $689 

Smart  Add  2  GB  additional  memory 

(PN:  40885 1-S21)  $159 


Lease  for  as  low  as  $39/mo‘  for  48  months 
Smart  (PN:  AG739A) 

•  400  GB  compressed  capacity  in  half-height 
form  factor 


*'  Pv,v* 

-  i 


1  Ships  with  Data  Protector  Express  Software, 
One  Button  Disaster  Recovery,  a  1U 
Rackmount  Kit,  and  a  Host  Bus  Adapter 


itU 


i -  ■  ’i  - ,  - . 


10,000,000  I.T.  folks  can't  be 


To  learn  more,  call  1-888-220-7138  or  visit  hp.com/go/dependablel4 


Prices  shown  are  HP  Direct  prices;  reseller  and  retail  prices  may  vary.  Prices  shown  are  subject  to  change  and  do  not  include  applicable  state  and  local  taxes  or  shipping  to  recipient's  address. 
Offers  cannot  be  combined  with  any  other  offer  or  discount  and  are  good  while  supplies  last.  All  featured  offers  available  in  U.S.  only.  Savings  based  on  HP  published  list  prices  of  configure-to-order 
equivalent  ($3125  -  $850  instant  savings  =  SmartBuy  price  of  $2,275).  1.  Financing  available  through  Hewlett-Packard  Financial  Services  Company  (HPFS)  to  qualified  commercial  customers  in 
the  U.S.  and  subject  to  credit  approval  and  execution  of  standard  HPFS  documentation.  Prices  shown  are  based  on  a  lease  of  48  months  in  terms  with  a  fair  market  value  purchase  option  at  the 
end  of  the  term.  Rates  based  on  an  original  transaction  size  between  $3,000  and  $25,000.  Other  rates  apply  for  other  terms  and  transaction  sizes.  Financing  available  on  transactions  greater  than 
$349  through  September  30, 2008.  HPFS  reserves  the  right  to  change  or  cancel  these  programs  at  any  time  without  notice.  AMD,  the  AMD  Arrow  logo,  AMD  Opteron,  and  combinations  thereof  are 
trademarks  of  Advanced  Micro  Devices,  Inc.  (c)  2008  Hewlett-Packard  Development  Company,  L.P.  The  information  contained  herein  is  subject  to  change  without  notice. 


